Skip to main content
Vulnerability Database/CVE-2026-81429

CVE-2026-81429: WPBakery Page Builder Export Plugin XSS

CVE-2026-81429 is a stored cross-site scripting vulnerability in the Export & Import WPBakery Page Builder WordPress plugin that exploits missing CSRF protection. This post covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-81429 Overview

CVE-2026-81429 affects the Export & Import WPBakery Page Builder WordPress plugin through version 1.0.2. The plugin lacks a Cross-Site Request Forgery (CSRF) check on its template-import feature and fails to sanitize imported data before storing and echoing it back. An attacker can craft a malicious request that, when triggered by a logged-in administrator, imports a template payload that executes Stored Cross-Site Scripting (XSS) in the administrator's browser session.

Critical Impact

Successful exploitation runs attacker-controlled JavaScript in an administrator session, enabling account takeover, plugin installation, and persistent backdoors within the WordPress site.

Affected Products

  • Export & Import WPBakery Page Builder WordPress plugin, versions up to and including 1.0.2
  • WordPress installations with the vulnerable plugin activated
  • Administrator accounts authenticated to the WordPress dashboard

Discovery Timeline

  • 2026-09-12 - CVE-2026-81429 published to the National Vulnerability Database (NVD)
  • 2026-09-14 - Last updated in NVD database

Technical Details for CVE-2026-81429

Vulnerability Analysis

The vulnerability chains two distinct weaknesses in the plugin's template-import workflow. First, the import endpoint does not verify a WordPress nonce or other anti-CSRF token, so any authenticated administrator visiting an attacker-controlled page can be forced to submit an import request. Second, the plugin stores the imported template data without sanitization and later renders it back into the administrator interface without output encoding.

This combination maps to Improper Neutralization of Input During Web Page Generation [CWE-79]. Because the payload persists in the database, it re-executes on every subsequent visit to the affected admin page until the malicious content is removed.

Root Cause

The plugin omits two standard WordPress defenses. The template-import handler does not call check_admin_referer() or wp_verify_nonce() before processing the request, leaving the action open to forged submissions. It also fails to apply sanitization functions such as wp_kses_post() on input, or escaping functions such as esc_html() or esc_attr() on output. Untrusted template content is therefore treated as trusted HTML in the administrator context.

Attack Vector

Exploitation requires user interaction from a logged-in administrator, typically achieved by luring them to a page under attacker control. The malicious page issues a forged POST request to the plugin's template-import endpoint containing a crafted template that includes HTML or JavaScript payloads. Once imported, the payload is stored server-side and executes whenever the administrator views the template within the WordPress dashboard. Full technical details are available in the WPScan Vulnerability Report.

Detection Methods for CVE-2026-81429

Indicators of Compromise

  • Unexpected <script>, <iframe>, or event-handler attributes (onerror, onload) present in stored WPBakery templates within the WordPress database.
  • Outbound HTTP requests from administrator browsers to unfamiliar domains after visiting the plugin's template pages.
  • New administrator accounts, modified user roles, or unfamiliar plugins installed shortly after a template import event.

Detection Strategies

  • Audit wp_posts and plugin-specific tables for template records containing HTML or JavaScript payloads.
  • Review web server access logs for POST requests to the template-import endpoint that lack a valid Referer header pointing to the WordPress admin.
  • Monitor for administrator sessions that generate unexpected AJAX or REST API calls immediately after loading a template page.

Monitoring Recommendations

  • Enable WordPress activity logging to capture plugin configuration changes, template imports, and user role modifications.
  • Correlate browser-side content security policy (CSP) violation reports with administrator dashboard activity.
  • Alert on creation of new administrator role users or changes to the site's active theme and plugin list.

How to Mitigate CVE-2026-81429

Immediate Actions Required

  • Deactivate and remove the Export & Import WPBakery Page Builder plugin until a patched version is confirmed available.
  • Rotate credentials and invalidate active sessions for all WordPress administrator accounts.
  • Inspect stored templates and remove any records containing untrusted HTML or scripting content.

Patch Information

No fixed version is identified in the referenced advisory as of the last NVD update. Monitor the WPScan Vulnerability Report and the plugin's WordPress.org listing for a security release addressing versions through 1.0.2.

Workarounds

  • Restrict access to the WordPress admin interface using IP allowlisting or a VPN to reduce CSRF exposure.
  • Deploy a Web Application Firewall (WAF) rule that blocks POST requests to the plugin's import endpoint without a valid WordPress nonce.
  • Enforce a strict Content Security Policy on the WordPress admin to limit execution of inline and remote scripts.
  • Train administrators to log out of the WordPress dashboard when browsing untrusted sites.
bash
# Configuration example: disable the plugin via WP-CLI until a patch is available
wp plugin deactivate export-import-wpbakery-page-builder
wp plugin delete export-import-wpbakery-page-builder

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.