PT-2025-32348 · WordPress · Wpbakery Page Builder+1

Krugov Artyom

·

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2025-6572

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) versions through 1.2.0
Description The plugin does not validate and escape certain block options before displaying them on a page or post, potentially allowing users with contributor roles and above to execute Stored Cross-Site Scripting attacks.
Recommendations Update OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) to a version later than 1.2.0.

Exploit

Fix

Related Identifiers

CVE-2025-6572

Affected Products

Openstreetmap For Gutenberg
Wpbakery Page Builder