Junglewise Threat Intelligence

CVE-2026-57780: Plugin Envision Envision Page Builder DOM-based XSS

CVE-2026-57780 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

Envision Page Builder, a WordPress plugin used for designing website layouts, contains a security flaw that could allow an attacker to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially redirect users to malicious websites, display unauthorized advertisements, or steal session information. This vulnerability requires the attacker to have at least contributor-level access to the site.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Envision Page Builder plugin (envision-page-builder) for WordPress. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts into the Document Object Model (DOM). Exploitation requires 'Contributor' level privileges and involves tricking a victim into performing an action, such as clicking a malicious link (User Interaction). Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session. As of the advisory date, no official patch is available for version 0.22.

Affected products

  • Plugin Envision Envision Page Builder <= 0.22

Timeline

  • 2026-01-13: disclosed: Vulnerability reported by Jitlada to Patchstack.
  • 2026-07-13: advisory: CVE published and NVD record created.

References