Broken Access Control in Visual Composer Website Builder by Visual Composer
CVE-2026-65568
5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-65568?
A vulnerability exists in the Visual Composer Website Builder that allows for broken access control, potentially enabling unauthorized users to perform actions they should not be permitted to. This issue affects versions up to 45.15.0 and may lead to escalated privileges that compromise the integrity of the website.
Affected Version(s)
Visual Composer Website Builder <= 45.15.0
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program