Cross Site Scripting Vulnerability in Visual Composer Website Builder
CVE-2026-97262
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-97262?
The Visual Composer Website Builder plugin for WordPress is prone to a Cross Site Scripting (XSS) vulnerability, which affects versions up to 45.16.2. This security flaw allows attackers to inject malicious scripts into web pages, putting users at risk when they interact with the compromised site. It is important for users of this plugin to update to a patched version to mitigate the risk of exploitation.
Affected Version(s)
Visual Composer Website Builder <= 45.16.2