The popular page-builder plugin WPBakery, installed in over 4 million websites, was discovered to host a critical flaw that allowed for attackers with contributor-level or above permissions, to inject malicious JavaScript in posts.
After a long period of patch development by the plugin team, a working patch was finally released on September 24, 2020.
We highly recommend updating to the latest version immediately (version 6.4.1 or higher). Simultaneously, we also recommend double-checking your website user list to make sure that no untrusted contributor-level or higher accounts have made their way inside.
For more information, please check the official public release.
If you have questions, don’t hesitate to contact our support team.
Leave a Reply