CVE-2025-11161

WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes in the font_container parameter. This makes it possible for authenticated attackers with contributor-level access or higher to inject arbitrary web scripts in posts that will execute whenever a user accesses an injected page via the vc_custom_heading shortcode with malicious tag and text attributes granted they have access to use WPBakery shortcodes.


We have discovered 1,101,202 live websites that are affected by CVE-2025-11161.

Run a Free Instant Scan




Affected Software

Product  WPBakery
Category Wordpress Plugins
Vulnerable Domains1,101,202 live websites (87% of WPBakery install base)
Vulnerable Versions
  • from 0 through 8.6.1
Vulnerable Versions Count235 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)



Details

  • Published - Oct 15, 2025
  • Updated - Apr 8, 2026

Credits

  • Muhammad Yudha - DJ (finder)

Website Distribution by Country

Number of websites using CVE-2025-11161
United States294,522 websites



Germany113,169 websites
Italy68,253 websites
France66,529 websites
GB53,041 websites
Spain39,750 websites
Netherlands39,238 websites
Poland26,326 websites
Canada24,412 websites
Russia23,957 websites

Website Distribution by TLD

Number of websites using CVE-2025-11161
.com458,275 websites
.de61,592 websites
.it48,590 websites
.org39,611 websites
.nl35,200 websites
.co.uk32,771 websites
.fr26,534 websites
.net20,887 websites
.com.br20,605 websites
.com.au20,561 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11161

Top websites that are affected by CVE-2025-11161. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***
**********.com United States***
*************.uk United States*,***
*********.nl United States*,***
********.com United States*,***
****.eu Belgium*,***
***********.com Switzerland*,***
*********.com United States*,***
****.edu United States*,***
******.com United States*,***
See full domain list

FAQ

CVE-2025-11161 is Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in WPBakery
A total of 1,101,202 websites have been identified as vulnerable to CVE-2025-11161, based on global website indexing conducted by WebTechSurvey.
The WPBakery is affected by the CVE-2025-11161 vulnerability.
WPBakery versions up to and including 8.6.1 are vulnerable to CVE-2025-11161.