plugin

Visualcomposer Vulnerabilities

23 known security issues reported for the Visualcomposer WordPress plugin. Most recent disclosed Jul 24, 2026.

10 medium

Running Visualcomposer on your site? Check whether your installed version is affected.

Scan your site free

Visual Composer Website Builder <= 45.15.0 - Missing Authorization

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 45.15.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 45.15.0
Fixed in:
45.16.0
Disclosed:
Jul 24, 2026

CVE-2026-65568 on NVD →

Visual Composer Website Builder <= 45.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 45.13.0
Fixed in:
45.15.0
Disclosed:
Aug 14, 2025

CVE-2025-55709 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.15.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through n/a.

Affected:
up to 45.15.0
Fixed in:
45.15.0
Disclosed:
Aug 14, 2025

CVE-2025-55709 on NVD →

Visual Composer Website Builder <= 45.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 45.11.0
Fixed in:
45.12.0
Disclosed:
May 19, 2025

CVE-2025-48276 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.12.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.11.0.

Affected:
up to 45.12.0
Fixed in:
45.12.0
Disclosed:
May 19, 2025

CVE-2025-48276 on NVD →

Visual Composer Website Builder <= 45.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 45.10.0
Fixed in:
45.11.0
Disclosed:
Apr 22, 2025

CVE-2025-46254 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.11.0

unknown

<p>WordPress Visual Composer Website Builder Plugin <= 45.10.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Visual Composer Website Builder</p><p>Fixed in version 45.11.0 </p><p>Affected Version <= 45.10.0</p><p>CVE: CVE-2025-46254</p>

Affected:
up to 45.11.0
Fixed in:
45.11.0
Disclosed:
Apr 22, 2025

Visual Composer Website Builder [visualcomposer] < 45.11.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.

Affected:
up to 45.11.0
Fixed in:
45.11.0
Disclosed:
Apr 22, 2025

CVE-2025-46254 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.9.0

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in visualcomposer.Com Visual Composer Website Builder allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through 45.8.0.

Affected:
up to 45.9.0
Fixed in:
45.9.0
Disclosed:
Jun 4, 2024

CVE-2024-35653 on NVD →

Visual Composer Website Builder <= 45.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 45.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 45.8.0
Fixed in:
45.9.0
Disclosed:
Jun 3, 2024

CVE-2024-35653 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.7.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualcomposer Visual Composer Website Builder allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through 45.6.0.

Affected:
up to 45.7.0
Fixed in:
45.7.0
Disclosed:
Mar 19, 2024

CVE-2024-27997 on NVD →

Visual Composer Website Builder <= 45.6.0 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping. This makes it poss...

CVSS:
4.4
Affected:
up to 45.6.0
Fixed in:
45.7.0
Disclosed:
Mar 15, 2024

CVE-2024-27997 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.7.0

unknown

[en] The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escap...

Affected:
up to 45.7.0
Fixed in:
45.7.0
Disclosed:
Mar 13, 2024

CVE-2023-6880 on NVD →

Visual Composer Premium <= 45.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping o...

CVSS:
6.4
Affected:
up to 45.6.0
Fixed in:
45.7.0
Disclosed:
Feb 29, 2024

CVE-2023-6880 on NVD →

Visual Composer Website Builder [visualcomposer] < 27.0

unknown

[en] The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 27.0
Fixed in:
27.0
Disclosed:
Jun 7, 2023

CVE-2020-36722 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.0.1

unknown

[en] The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual compo...

Affected:
up to 45.0.1
Fixed in:
45.0.1
Disclosed:
Sep 6, 2022

CVE-2022-2516 on NVD →

Visual Composer Website Builder [visualcomposer] < 45.0.1

unknown

[en] The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer...

Affected:
up to 45.0.1
Fixed in:
45.0.1
Disclosed:
Sep 6, 2022

CVE-2022-2430 on NVD →

Visual Composer Website Builder <= 45.0 - Authenticated Stored Cross-Site Scripting via 'Title'

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer e...

CVSS:
6.4
Affected:
up to 45.0
Fixed in:
45.0.1
Disclosed:
Aug 29, 2022

CVE-2022-2516 on NVD →

Visual Composer Website Builder <= 45.0 - Authenticated Stored Cross-Site Scripting via 'Text Block'

medium

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer edit...

CVSS:
6.4
Affected:
up to 45.0
Fixed in:
45.0.1
Disclosed:
Aug 29, 2022

CVE-2022-2430 on NVD →

Visual Composer <= 26.0 - Multiple Cross-Site Scripting

medium

The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.5
Affected:
up to 26.0
Fixed in:
27.0
Disclosed:
May 18, 2020

CVE-2020-36722 on NVD →

Visual Composer Website Builder [visualcomposer] < 27.0

unknown

The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 27.0
Fixed in:
27.0
Disclosed:
May 18, 2020

Visual Composer Website Builder [visualcomposer] < 27.0

unknown

Multiple Cross-Site Scripting (XSS) vulnerabilities discovered by NinTechNet in WordPress Visual Composer Website Builder plugin (versions <= 26.0).

Affected:
up to 27.0
Fixed in:
27.0
Disclosed:
May 18, 2020

Visual Composer Website Builder [visualcomposer] < 27.0

unknown

Jerome Braundet from NinTechNet, discovered multiple Stored Cross-Site Scripting issues, which could allow users with the contributor and above roles to inject arbitrary JavaScript in the blog.

Affected:
up to 27.0
Fixed in:
27.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database