Stored XSS Vulnerability in Visual Composer Website Builder by Visual Composer
CVE-2025-48276
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 May 2025
What is CVE-2025-48276?
A vulnerability in the Visual Composer Website Builder allows attackers to execute Stored Cross-site Scripting (XSS) attacks. This security flaw occurs due to improper neutralization of input during web page generation. Malicious actors could exploit this vulnerability on versions ranging from n/a through 45.11.0, potentially compromising user data and website integrity. It is crucial for users and website administrators to apply available patches or updates to mitigate the risk.
Affected Version(s)
Visual Composer Website Builder <= 45.11.0