Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39703

24
FAUCET Score

CVE-2026-39703 is a Stored Cross-Site Scripting (XSS) vulnerability in WPBITS Addons For Elementor Page Builder affecting versions 1.8.1 and earlier. The vulnerability exists in the plugin's improper neutralization of user input during web page generation, allowing attackers to inject and store malicious scripts within the application. This vulnerability can compromise WordPress installations that utilize this popular page builder extension. The vulnerability carries a CVSS 6.5 Medium severity rating with a network-based attack vector requiring low complexity and low privileges to execute. An attacker must have valid user authentication and user interaction to succeed, but once exploited, the attack has cross-site consequences affecting confidentiality, integrity, and availability for potential victims. The threat remains relatively contained due to authentication requirements, though the stored XSS nature allows for persistent impact. Exploitation of this vulnerability is currently not actively documented in public exploit databases, with no advisories indicating widespread exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and community attention remains minimal based on its low EPSS score of 0.00034. Organizations using this plugin should apply security updates to version 1.8.2 or later, though immediate patching urgency is moderate given the lack of active exploitation evidence.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 1.8.1CPE match
cpe:2.3:a:wpbits:wpbits_addons_for_elementor_page_builder:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 1st percentile among its peer group of 15,225 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/wpbits-addons-for-elementor/vulnerability/wordpress-wpbits-addons-for-elementor-page-builder-plugin-1-8-1-cross-site-scripting-xss-vulnerability