Executive brief
Visual Composer Website Builder is a popular WordPress plugin used to design and build website layouts. A security flaw in versions 45.15.0 and earlier allows users with 'Contributor' level access to perform actions they should not be authorized to do. While this requires an existing account on the site, it could allow lower-level staff or guest authors to modify site settings or content beyond their intended permissions.
Technical details
A broken access control vulnerability exists in the Visual Composer Website Builder plugin for WordPress (versions <= 45.15.0) due to missing authorization checks (CWE-862). An authenticated attacker with Contributor-level privileges can exploit this flaw over the network to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability is characterized by a lack of proper validation of user permissions or nonce tokens for specific plugin actions. The issue is resolved in version 45.16.0.
Affected products
- Visual Composer Visual Composer Website Builder <= 45.15.0
Timeline
- 2026-07-14: other: Reported by researcher Ananda Dhakal
- 2026-07-24: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD