Executive brief
The Builderall for WordPress plugin, used to build and design website pages, contains a vulnerability in its Photo Module that allows authenticated contributors to inject malicious scripts. When an administrator or other user views an affected page, the injected script runs automatically, potentially compromising their account or stealing sensitive information.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Photo Module's 'attributes' setting, arising from insufficient input sanitization and output escaping. An authenticated attacker with contributor-level access or higher can inject arbitrary JavaScript code that persists in the database. The malicious script executes in the browser of any user who accesses the affected page, potentially enabling session hijacking, credential theft, or further site compromise. The vulnerability affects Builderall for WordPress versions up to and including 3.0.2.
Affected products
- Builderall Builderall for WordPress up to and including 3.0.2
Timeline
- 2026-09-10: disclosed