Executive brief
Visual Composer Website Builder is a popular WordPress page builder plugin used by thousands of websites to create and manage page layouts. A cross-site scripting (XSS) vulnerability in versions 45.16.1 and earlier allows contributor-level users to inject malicious JavaScript code that could steal visitor data, hijack user accounts, or spread malware across the website.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Visual Composer Website Builder plugin versions up to 45.16.1. The vulnerability requires contributor-level or higher privileges to exploit—a user cannot be tricked into performing an action; rather, a malicious contributor must deliberately inject the payload. An attacker with contributor access can inject arbitrary JavaScript into the page builder interface that executes in the context of visitor browsers, potentially stealing session tokens, hijacking accounts, or performing unauthorized actions. The vulnerability has been patched in version 45.16.2 and later.
Affected products
- Visual Composer Website Builder <= 45.16.1
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 45.16.2