Junglewise Threat Intelligence

CVE-2026-81429: Export & Import WPBakery Page Builder stored XSS via CSRF

CVE-2026-81429 · Severity: high · CVSS 7.1 · Published 2026-09-12

Executive brief

The Export & Import WPBakery Page Builder WordPress plugin (used to manage page builder templates) contains a critical flaw in its template import feature that lacks both CSRF protection and input validation. An attacker can trick an administrator into importing a malicious template through a forged request, resulting in malicious code execution within the administrator's browser session with full site access.

Technical details

The plugin fails to implement CSRF tokens on its template-import endpoint and does not sanitize or escape imported data before storing and displaying it. An attacker can craft a malicious template file containing JavaScript payloads and trick an authenticated administrator into importing it via a cross-site request (e.g., through a crafted webpage). The unsanitized data is then stored in the database and executed in the administrator's session when the template is viewed or managed. This is a stored XSS vulnerability requiring admin-level access to trigger, with no known patch available as of the advisory date.

Affected products

  • WPBakery Export & Import WPBakery Page Builder through 1.0.2

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: advisory

References