Project Subscriptions
No advisories yet.
Solution
Update the WordPress Ultimate Addons for WPBakery Page Builder Plugin to the latest available version (at least 3.21.4).
Workaround
No workaround given by the vendor.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brainstormforce
Brainstormforce ultimate Addons For Wpbakery Page Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brainstormforce
Brainstormforce ultimate Addons For Wpbakery Page Builder Wordpress Wordpress wordpress |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4. | |
| Title | WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.4 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-01T13:29:40.506Z
Reserved: 2026-03-31T09:57:17.719Z
Link: CVE-2026-34889
Updated: 2026-04-01T13:29:29.911Z
Status : Awaiting Analysis
Published: 2026-04-01T09:16:17.457
Modified: 2026-04-01T14:23:37.727
Link: CVE-2026-34889
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:17:47Z