CVE-2026-15101 | WPBakery Page Builder Plugin up to 8.7.4 on WordPress vc_raw_html shortcode data HTML injection

SecurityVulns

A vulnerability was found in WPBakery Page Builder Plugin up to 8.7.4 on WordPress. It has been rated as problematic. This vulnerability affects the function vc_raw_html of the component vc_raw_html shortcode. The manipulation of the argument data leads to HTML injection.

This vulnerability is referenced as CVE-2026-15101. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More