
CVE-2026-13295 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.… https://www.cve.org/CVERecord?id=CVE-2026-13295
Post summary
The post only discloses a stored XSS flaw in SiteOrigin’s Page Builder plugin, providing the affected parameter and version range, but offers no PoC, exploit code, or patch information.

