PT-2026-69039 · WordPress · Wp Page Builder
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SP Page Builder versions prior to 6.7.0
Description
An unauthenticated attacker can perform a stored Cross-Site Scripting (XSS) attack—where malicious scripts are permanently stored on the target server—by sending a single HTTP request to the Shapes API endpoint. The stored JavaScript executes automatically in the browser of an administrator when they open the SP Page Builder editor.
Recommendations
Update SP Page Builder to version 6.7.0 or later.
Fix
XSS
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Page Builder