Executive brief
The Export & Import WPBakery Page Builder WordPress plugin (used to manage page builder templates) contains a critical flaw in its template import feature that lacks both CSRF protection and input validation. An attacker can trick an administrator into importing a malicious template through a forged request, resulting in malicious code execution within the administrator's browser session with full site access.
Technical details
The plugin fails to implement CSRF tokens on its template-import endpoint and does not sanitize or escape imported data before storing and displaying it. An attacker can craft a malicious template file containing JavaScript payloads and trick an authenticated administrator into importing it via a cross-site request (e.g., through a crafted webpage). The unsanitized data is then stored in the database and executed in the administrator's session when the template is viewed or managed. This is a stored XSS vulnerability requiring admin-level access to trigger, with no known patch available as of the advisory date.
Affected products
- WPBakery Export & Import WPBakery Page Builder through 1.0.2
Timeline
- 2026-09-10: disclosed
- 2026-09-12: advisory