Input validation vulnerability in WPBakery Visual Composer 7.5

The wpbakery plugin used in WordPress is at risk of being attacked by malicious code through the Custom Heading tag feature. This can happen in all versions up to 7.5 because the plugin does not properly clean or secure the input and output of data. This means that someone who has access to the website, like a contributor or higher, can insert harmful scripts into pages which will run whenever someone visits that page.

Detected in:

WPBakery Page Builder fixed vulnerable versions:
WPBakery Page Builder for WordPress fixed vulnerable versions: >= * <= 7.5
WPBakery Visual Composer fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.