Brainstormforce Ultimate Addons Wpbakery Page Builder
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Brainstormforce Ultimate Addons Wpbakery Page Builder.
By the Year
In 2026 there have been 1 vulnerability in Brainstormforce Ultimate Addons Wpbakery Page Builder with an average score of 6.5 out of ten. Ultimate Addons Wpbakery Page Builder did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.50 |
| 2025 | 0 | 0.00 |
| 2024 | 6 | 6.40 |
| 2023 | 2 | 7.10 |
It may take a day or so for new Ultimate Addons Wpbakery Page Builder vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Ultimate Addons Wpbakery Page Builder Security Vulnerabilities
Missing Auth in Brainstorm Force UAPB <=3.21.1 Allows Access Exploit
CVE-2026-28038
6.5 - Medium
- March 05, 2026
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1.
AuthZ
Stored XSS via ultimate_dual_color in Ultimate Addons WPBakery 3.19.20
CVE-2024-5255
6.4 - Medium
- July 17, 2024
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Ultimate Addons WPBakery 3.19.20 Stored XSS in ultimate_info_banner
CVE-2024-5254
6.4 - Medium
- July 17, 2024
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
XSS in Ultimate Addons for WPBakery upto 3.19.20 via ult_team shortcode
CVE-2024-5253
6.4 - Medium
- July 17, 2024
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Ultimate Addons for WPBakery v3.19.20: Stored XSS via ultimate_info_table
CVE-2024-5252
6.4 - Medium
- July 17, 2024
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Stored XSS in Ultimate Addons for WPBakery <=3.19.20 via ultimate_pricing
CVE-2024-5251
6.4 - Medium
- July 17, 2024
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
WP Plugin Ultimate Addons < 3.19.14 Path Traversal LFI
CVE-2023-46205
- May 17, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.
Directory traversal
Brain Storm Force Ultimate Addons WPBakery CSRF <=3.19.17
CVE-2023-51402
8.8 - High
- December 29, 2023
Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17.
Session Riding
Stored XSS in Brainstorm Force Ultimate Addons WPBakery <=3.19.14
CVE-2023-46211
5.4 - Medium
- October 27, 2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Brainstormforce Ultimate Addons Wpbakery Page Builder or by Brainstormforce? Click the Watch button to subscribe.