VYPR
Unrated severityNVD Advisory· Published Apr 3, 2023· Updated Feb 14, 2025

Image Over Image For WPBakery Page Builder < 3.0 - Contributor+ Stored XSS

CVE-2023-0399

Description

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Image Over Image For WPBakery Page Builder plugin before 3.0 is vulnerable to stored XSS via unescaped shortcode attributes, allowing contributor-level users to inject malicious scripts.

Vulnerability

The Image Over Image For WPBakery Page Builder WordPress plugin before version 3.0 fails to validate and escape some of its shortcode attributes before outputting them back in a page or post where the shortcode is embedded. This allows users with the contributor role and above to inject arbitrary HTML and JavaScript. [1]

Exploitation

An attacker with at least contributor-level access can create or edit a post/page and insert the vulnerable shortcode with crafted attribute values containing malicious JavaScript. When the post/page is viewed by any user, the injected script executes in the context of the victim's browser. No additional user interaction is required beyond viewing the affected content. [1]

Impact

Successful exploitation results in stored cross-site scripting (XSS). The attacker can execute arbitrary JavaScript in the browsers of users who visit the compromised page, potentially leading to session hijacking, credential theft, defacement, or redirection to malicious sites. The attack is persistent and affects all visitors. [1]

Mitigation

The vulnerability is fixed in version 3.0 of the plugin. Users are strongly advised to update to 3.0 or later immediately. No workarounds are provided in the available references. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.