Impact
A cross‑site scripting vulnerability exists in the Visual Composer Website Builder plugin for WordPress versions 45.16.1 and earlier. The flaw allows a contributor or even an unauthenticated user to inject arbitrary JavaScript by submitting unsanitized content into specific input fields. The injected code can execute in the browsers of visitors who view the affected pages, potentially leading to cookie theft, session hijacking, or defacement of published content. This weakness is classified as CWE‑79.
Affected Systems
WordPress sites that install the Visual Composer Website Builder plugin with any version up to and including 45.16.1 are vulnerable. Owners running these versions, or any sites that accept content from contributors using the editor, are at risk.
Risk and Exploitability
The vulnerability has a CVSS v3 score of 6.5, marking it as moderate severity, and an EPSS score of less than 1 %, indicating a low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. Attackers could exploit the flaw by embedding malicious JavaScript in editable content or by persuading a contributor to submit a crafted payload. Successful exploitation requires that the front‑end editor code remains unpatched and that the site does not sanitize user input before rendering.
OpenCVE Enrichment