Visual Composer Website Builder <= 45.15.0 - Missing Authorization
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 45.15.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 45.15.0
- Fixed in:
- 45.16.0
- Disclosed:
- Jul 24, 2026
CVE-2026-65568 on NVD →
Visual Composer Website Builder <= 45.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 45.13.0
- Fixed in:
- 45.15.0
- Disclosed:
- Aug 14, 2025
CVE-2025-55709 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.15.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through n/a.
- Affected:
- up to 45.15.0
- Fixed in:
- 45.15.0
- Disclosed:
- Aug 14, 2025
CVE-2025-55709 on NVD →
Visual Composer Website Builder <= 45.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 45.11.0
- Fixed in:
- 45.12.0
- Disclosed:
- May 19, 2025
CVE-2025-48276 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.12.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.11.0.
- Affected:
- up to 45.12.0
- Fixed in:
- 45.12.0
- Disclosed:
- May 19, 2025
CVE-2025-48276 on NVD →
Visual Composer Website Builder <= 45.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 45.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 45.10.0
- Fixed in:
- 45.11.0
- Disclosed:
- Apr 22, 2025
CVE-2025-46254 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.11.0
unknown
<p>WordPress Visual Composer Website Builder Plugin <= 45.10.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Visual Composer Website Builder</p><p>Fixed in version 45.11.0 </p><p>Affected Version <= 45.10.0</p><p>CVE: CVE-2025-46254</p>
- Affected:
- up to 45.11.0
- Fixed in:
- 45.11.0
- Disclosed:
- Apr 22, 2025
Visual Composer Website Builder [visualcomposer] < 45.11.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.
- Affected:
- up to 45.11.0
- Fixed in:
- 45.11.0
- Disclosed:
- Apr 22, 2025
CVE-2025-46254 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.9.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in visualcomposer.Com Visual Composer Website Builder allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through 45.8.0.
- Affected:
- up to 45.9.0
- Fixed in:
- 45.9.0
- Disclosed:
- Jun 4, 2024
CVE-2024-35653 on NVD →
Visual Composer Website Builder <= 45.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 45.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary...
- CVSS:
- 4.4
- Affected:
- up to 45.8.0
- Fixed in:
- 45.9.0
- Disclosed:
- Jun 3, 2024
CVE-2024-35653 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.7.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualcomposer Visual Composer Website Builder allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through 45.6.0.
- Affected:
- up to 45.7.0
- Fixed in:
- 45.7.0
- Disclosed:
- Mar 19, 2024
CVE-2024-27997 on NVD →
Visual Composer Website Builder <= 45.6.0 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping. This makes it poss...
- CVSS:
- 4.4
- Affected:
- up to 45.6.0
- Fixed in:
- 45.7.0
- Disclosed:
- Mar 15, 2024
CVE-2024-27997 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.7.0
unknown
[en] The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escap...
- Affected:
- up to 45.7.0
- Fixed in:
- 45.7.0
- Disclosed:
- Mar 13, 2024
CVE-2023-6880 on NVD →
Visual Composer Premium <= 45.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping o...
- CVSS:
- 6.4
- Affected:
- up to 45.6.0
- Fixed in:
- 45.7.0
- Disclosed:
- Feb 29, 2024
CVE-2023-6880 on NVD →
Visual Composer Website Builder [visualcomposer] < 27.0
unknown
[en] The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 27.0
- Fixed in:
- 27.0
- Disclosed:
- Jun 7, 2023
CVE-2020-36722 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.0.1
unknown
[en] The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual compo...
- Affected:
- up to 45.0.1
- Fixed in:
- 45.0.1
- Disclosed:
- Sep 6, 2022
CVE-2022-2516 on NVD →
Visual Composer Website Builder [visualcomposer] < 45.0.1
unknown
[en] The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer...
- Affected:
- up to 45.0.1
- Fixed in:
- 45.0.1
- Disclosed:
- Sep 6, 2022
CVE-2022-2430 on NVD →
Visual Composer Website Builder <= 45.0 - Authenticated Stored Cross-Site Scripting via 'Title'
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer e...
- CVSS:
- 6.4
- Affected:
- up to 45.0
- Fixed in:
- 45.0.1
- Disclosed:
- Aug 29, 2022
CVE-2022-2516 on NVD →
Visual Composer Website Builder <= 45.0 - Authenticated Stored Cross-Site Scripting via 'Text Block'
medium
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer edit...
- CVSS:
- 6.4
- Affected:
- up to 45.0
- Fixed in:
- 45.0.1
- Disclosed:
- Aug 29, 2022
CVE-2022-2430 on NVD →
Visual Composer <= 26.0 - Multiple Cross-Site Scripting
medium
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.5
- Affected:
- up to 26.0
- Fixed in:
- 27.0
- Disclosed:
- May 18, 2020
CVE-2020-36722 on NVD →
Visual Composer Website Builder [visualcomposer] < 27.0
unknown
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 27.0
- Fixed in:
- 27.0
- Disclosed:
- May 18, 2020
Visual Composer Website Builder [visualcomposer] < 27.0
unknown
Multiple Cross-Site Scripting (XSS) vulnerabilities discovered by NinTechNet in WordPress Visual Composer Website Builder plugin (versions <= 26.0).
- Affected:
- up to 27.0
- Fixed in:
- 27.0
- Disclosed:
- May 18, 2020
Visual Composer Website Builder [visualcomposer] < 27.0
unknown
Jerome Braundet from NinTechNet, discovered multiple Stored Cross-Site Scripting issues, which could allow users with the contributor and above roles to inject arbitrary JavaScript in the blog.
- Affected:
- up to 27.0
- Fixed in:
- 27.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database