← WordPress Vulnerabilities
WordPress security by component

Hybrid Composer

Hybrid Composer is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 04, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: hybrid-composer

CVE-2019-25738: Hybrid Composer: Privilege escalation or authentication bypass

Hybrid Composer is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is 1.4.6.

PublishedJun 04, 2026
Safe version guidanceSee mitigation notes
Safe version
Jun 04, 2026 CVE-2019-25738
Hybrid Composer: Privilege escalation or authentication bypass
Hybrid Composer is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is 1.4.6.
See mitigation notes
CVE9.3
NVDPending