Image Over Image For WPBakery Page Builder < 3.0 - Contributor+ Stored XSS
Description
The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Image Over Image For WPBakery Page Builder plugin before 3.0 is vulnerable to stored XSS via unescaped shortcode attributes, allowing contributor-level users to inject malicious scripts.
Vulnerability
The Image Over Image For WPBakery Page Builder WordPress plugin before version 3.0 fails to validate and escape some of its shortcode attributes before outputting them back in a page or post where the shortcode is embedded. This allows users with the contributor role and above to inject arbitrary HTML and JavaScript. [1]
Exploitation
An attacker with at least contributor-level access can create or edit a post/page and insert the vulnerable shortcode with crafted attribute values containing malicious JavaScript. When the post/page is viewed by any user, the injected script executes in the context of the victim's browser. No additional user interaction is required beyond viewing the affected content. [1]
Impact
Successful exploitation results in stored cross-site scripting (XSS). The attacker can execute arbitrary JavaScript in the browsers of users who visit the compromised page, potentially leading to session hijacking, credential theft, defacement, or redirection to malicious sites. The attack is persistent and affects all visitors. [1]
Mitigation
The vulnerability is fixed in version 3.0 of the plugin. Users are strongly advised to update to 3.0 or later immediately. No workarounds are provided in the available references. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/702d7bbe-93cc-4bc2-b41d-cb66e08c99a7mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.