CVE-2026-81429 PUBLISHED

Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF

Assigner: WPScan
Reserved: 26.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.

Product Status

Vendor Unknown
Product Export & Import WPBakery Page Builder
Versions Default: unknown
  • affected from 0 to 1.0.2 (incl.)

Credits

  • Suhayb Ahmed (cyboltx) finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE