WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Page Builder by SiteOrigin

Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.

8Reported vulnerabilities
8.8Highest CVSS score
2.36.0Latest version
400,000+Active installs

What to do now

Update Page Builder by SiteOrigin to 2.34.4 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 4, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-13643 High 8.8 0.8% Before 2.10.16 2.10.16 May 28, 2020
CVE-2020-13642 High 8.8 0.8% Before 2.10.16 2.10.16 May 28, 2020
CVE-2026-2448 High 8.8 0.9% 0 to 2.33.5 (inclusive) 2.34.0 March 3, 2026
CVE-2026-13295 Medium 6.4 0.4% 0 to 2.34.3 (inclusive) 2.34.4 June 27, 2026
CVE-2024-12240 Medium 5.4 0.3% Before 2.31.1 2.31.1 January 14, 2025
CVE-2024-4361 Medium 5.4 0.4% Before 2.29.16 2.29.16 May 21, 2024
CVE-2024-2202 Medium 5.4 0.4% Before 2.29.7 2.29.7 March 23, 2024
WF-d10364ed-179d-4506-a6f0-42b03c005242 Medium 5.3 Before 2.0.5 2.0.5 December 1, 2015

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.