Description
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

A cross‑site scripting vulnerability exists in the Visual Composer Website Builder plugin for WordPress versions 45.16.1 and earlier. The flaw allows a contributor or even an unauthenticated user to inject arbitrary JavaScript by submitting unsanitized content into specific input fields. The injected code can execute in the browsers of visitors who view the affected pages, potentially leading to cookie theft, session hijacking, or defacement of published content. This weakness is classified as CWE‑79.

Affected Systems

WordPress sites that install the Visual Composer Website Builder plugin with any version up to and including 45.16.1 are vulnerable. Owners running these versions, or any sites that accept content from contributors using the editor, are at risk.

Risk and Exploitability

The vulnerability has a CVSS v3 score of 6.5, marking it as moderate severity, and an EPSS score of less than 1 %, indicating a low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. Attackers could exploit the flaw by embedding malicious JavaScript in editable content or by persuading a contributor to submit a crafted payload. Successful exploitation requires that the front‑end editor code remains unpatched and that the site does not sanitize user input before rendering.

Generated by OpenCVE AI on September 21, 2026 at 04:09 UTC.

Remediation

Vendor Solution

Update the WordPress Visual Composer Website Builder Plugin to the latest available version (at least 45.16.2).


OpenCVE Recommended Actions

  • Update the Visual Composer Website Builder plugin to the latest available version (45.16.2 or later).
  • If a patch is not immediately available, disable or remove any widget or field that accepts raw text to block script injection.
  • Clear site‑wide caches so the updated state takes effect immediately.

Generated by OpenCVE AI on September 21, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Visualcomposer
Visualcomposer visual Composer Website Builder
Wordpress
Wordpress wordpress
Vendors & Products Visualcomposer
Visualcomposer visual Composer Website Builder
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
Title WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Visualcomposer Visual Composer Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T19:40:26.682Z

Reserved: 2026-07-13T06:15:23.737Z

Link: CVE-2026-62138

cve-icon Vulnrichment

Updated: 2026-09-11T19:40:22.463Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:45.270

Modified: 2026-09-11T21:17:02.457

Link: CVE-2026-62138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')