Input validation vulnerability in WPBakery Page Builder 8.6.1

The WPBakery Page Builder plugin for WordPress has a security issue that can be exploited by hackers. This is because the plugin does not properly limit which HTML tags can be used, and it also does not properly clean up user input. This means that attackers with certain levels of access can insert harmful code into posts using a specific shortcode, and this code will run when someone views the post.

Detected in:

WPBakery Page Builder fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.