Showing 1 vulnerability on this page for WC Builder – WooCommerce Page Builder for WPBakery

Signals CISA KEV Ransomware Nuclei
HasThemes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WC Builder <= 1.2.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'heading_color' Shortcode Attribute

The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other styling parameters) of the `wpbforwpbakery_product_additional_information` shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary web scripts in pages t

CWE-79Dec 21, 2025
CVSS4.4v3.1EPSS0.207%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX