Description
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
Published: 2026-07-27
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw in the Visual Composer Website Builder WordPress plugin versions 45.15.0 and earlier, classified as CWE‑862. It permits an attacker to perform privileged actions that the plugin’s normal authorization model should prevent, such as modifying or removing website content outside of the intended user scope.

Affected Systems

Any WordPress installation that includes the Visual Composer Website Builder plugin with a version of 45.15.0 or older is affected. The vulnerability specifically targets the plugin component named Visual Composer within the Visual Composer:Visual Composer Website Builder product line.

Risk and Exploitability

The CVSS score of 5 indicates a moderate level of severity. The EPSS score of <1% indicates a very low, but non-zero, probability that this vulnerability will be exploited. The vulnerability is not listed in the CISA KEV catalog, and no official exploit references are currently available. Attackers would need to have a way to interact with the plugin, likely through an exposed web interface, to take advantage of the broken authorization checks.

Generated by OpenCVE AI on August 3, 2026 at 17:27 UTC.

Remediation

Vendor Solution

Update the WordPress Visual Composer Website Builder Plugin to the latest available version (at least 45.16.0).


OpenCVE Recommended Actions

  • Update the Visual Composer Website Builder plugin to version 45.16.0 or newer.
  • Remove or disable any legacy copies of the plugin that might still be installed on the server.
  • Review recent content changes and audit logs for unauthorized modifications that may have occurred before the patch.

Generated by OpenCVE AI on August 3, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Visualcomposer
Visualcomposer visual Composer Website Builder
Wordpress
Wordpress wordpress
Vendors & Products Visualcomposer
Visualcomposer visual Composer Website Builder
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
Title WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Visualcomposer Visual Composer Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:17:37.177Z

Reserved: 2026-07-22T08:54:32.759Z

Link: CVE-2026-65568

cve-icon Vulnrichment

Updated: 2026-07-27T15:12:44.154Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:10.217

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-65568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses