Broken Access Control in Visual Composer Website Builder by Visual Composer
CVE-2026-65568

5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65568?

A vulnerability exists in the Visual Composer Website Builder that allows for broken access control, potentially enabling unauthorized users to perform actions they should not be permitted to. This issue affects versions up to 45.15.0 and may lead to escalated privileges that compromise the integrity of the website.

Affected Version(s)

Visual Composer Website Builder <= 45.15.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.