Impact
The vulnerability is a broken access control flaw in the Visual Composer Website Builder WordPress plugin versions 45.15.0 and earlier, classified as CWE‑862. It permits an attacker to perform privileged actions that the plugin’s normal authorization model should prevent, such as modifying or removing website content outside of the intended user scope.
Affected Systems
Any WordPress installation that includes the Visual Composer Website Builder plugin with a version of 45.15.0 or older is affected. The vulnerability specifically targets the plugin component named Visual Composer within the Visual Composer:Visual Composer Website Builder product line.
Risk and Exploitability
The CVSS score of 5 indicates a moderate level of severity. The EPSS score of <1% indicates a very low, but non-zero, probability that this vulnerability will be exploited. The vulnerability is not listed in the CISA KEV catalog, and no official exploit references are currently available. Attackers would need to have a way to interact with the plugin, likely through an exposed web interface, to take advantage of the broken authorization checks.
OpenCVE Enrichment