Junglewise Threat Intelligence

CVE-2026-45436: WPBakery Page Builder broken access control in WordPress plugin

CVE-2026-45436 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Executive brief

WPBakery Page Builder, a popular tool for designing WordPress websites, contains a security flaw that allows low-level users to perform actions they should not be authorized to do. An attacker with a basic 'Subscriber' account could exploit this to modify site content or settings, potentially disrupting operations or defacing the website. This vulnerability is particularly concerning as it can be targeted in automated mass-exploit campaigns against WordPress sites.

Technical details

A broken access control vulnerability (CWE-862) exists in WPBakery Page Builder (formerly Visual Composer) versions <= 8.7.2. The flaw stems from missing authorization checks in certain functions, allowing an authenticated user with Subscriber-level privileges to execute actions intended for higher-privileged roles. The attack vector is network-based and requires low privileges but no user interaction. Successful exploitation allows an attacker to compromise the integrity of the site by performing unauthorized modifications. The issue is resolved in version 8.7.3.

Affected products

  • Rain-Task Ltd. WPBakery Page Builder <= 8.7.2

Timeline

  • 2026-05-11: other: Reported by Ethan Consulting
  • 2026-05-13: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: NVD publication date
  • 2026-05-13: patched: Version 8.7.3 released

References