CVE-2026-34889: WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34889?
CVE-2026-34889 has a severity rating that indicates a significant risk due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2026-34889?
To fix CVE-2026-34889, upgrade the Ultimate Addons for WPBakery Page Builder plugin to version 3.21.4 or later.
What types of attacks can CVE-2026-34889 facilitate?
CVE-2026-34889 can facilitate DOM-Based XSS attacks, potentially allowing attackers to execute malicious scripts in users' browsers.
Who is affected by CVE-2026-34889?
Users of the Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin prior to version 3.21.4 are affected by CVE-2026-34889.
What should I monitor for with CVE-2026-34889?
Monitor for unusual user activity or potentially malicious scripts being executed on pages that use the affected version of the plugin.