{"id":"CVE-2026-81429","title":"The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …","summary":"The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cwe":["CWE-79","CWE-352"],"product":"Export & Import WPBakery Page Builder","affected":["export_import_wpbakery_page_builder <= 1.0.2"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81429","references":[{"url":"https://wpscan.com/vulnerability/48f67510-9fb3-4f74-a38e-31635617ba60/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.0009,"epssPercentile":0.00512,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-12T15:22:47.586471Z"},"ingestedAt":"2026-09-14T15:23:07.478Z","slug":"CVE-2026-81429","body":"## Overview\n\nThe Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}