WordPress security by component
Visual Composer Website Builder
Plugin description
Visual Composer Website Builder provides a drag-and-drop visual editor for creating WordPress page layouts.
Visual Composer Website Builder (visualcomposer) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
visualcomposerLatest vulnerability
CVE-2026-62138: Visual Composer permits contributor cross-site scripting
Visual Composer Website Builder through 45.16.1 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62138
Visual Composer permits contributor cross-site scripting
Visual Composer Website Builder through 45.16.1 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
|
45.16.2 |
CVE6.5
NVDPending
|
| Jul 27, 2026 |
CVE-2026-65568
Visual Composer contributors can reach a privileged operation
Visual Composer Website Builder through 45.15.0 lets a Contributor reach a plugin operation without the required capability or ownership check.
|
45.16.0 |
CVE5.0
NVDPending
|
| Aug 14, 2025 |
CVE-2025-55709
Visual Composer Website Builder: Cross-site scripting
Visual Composer Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 19, 2025 |
CVE-2025-48276
Visual Composer Website Builder: Cross-site scripting
Visual Composer Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 04, 2024 |
CVE-2024-35653
Visual Composer Website Builder: Cross-site scripting
Visual Composer Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 19, 2024 |
CVE-2024-27997
Visual Composer Website Builder: Cross-site scripting
Visual Composer Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|