The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes in the font_container parameter. This makes it possible for authenticated attackers with contributor-level access or higher to inject arbitrary web scripts in posts that will execute whenever a user accesses an injected page via the vc_custom_heading shortcode with malicious tag and text attributes granted they have access to use WPBakery shortcodes.
We have discovered 1,101,202 live websites that are affected by CVE-2025-11161.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,101,202 live websites (87% of WPBakery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 235 versions ( 97% of all versions) |
| 294,522 websites | |
| 113,169 websites | |
| 68,253 websites | |
| 66,529 websites | |
| 53,041 websites | |
| 39,750 websites | |
| 39,238 websites | |
| 26,326 websites | |
| 24,412 websites | |
| 23,957 websites |
| .com | 458,275 websites |
| .de | 61,592 websites |
| .it | 48,590 websites |
| .org | 39,611 websites |
| .nl | 35,200 websites |
| .co.uk | 32,771 websites |
| .fr | 26,534 websites |
| .net | 20,887 websites |
| .com.br | 20,605 websites |
| .com.au | 20,561 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.********.com | *** | ||
| **********.com | *** | ||
| *************.uk | *,*** | ||
| *********.nl | *,*** | ||
| ********.com | *,*** | ||
| ****.eu | *,*** | ||
| ***********.com | *,*** | ||
| *********.com | *,*** | ||
| ****.edu | *,*** | ||
| ******.com | *,*** |
FAQ