Visual Composer Website Builder <= 45.16.3 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via 'vcv-source-id' Parameter

Medium 4.3 CWE-639Fixed in 45.16.4
ID
WPSEC-2026-0632
Plugin
Visual Composer Website Builder (visualcomposer)
Affected
all versions before 45.16.4
Remediation
Update to 45.16.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Visual Composer Website Builder on WPSec AttackSurface
Fix released
Published

Description

The Visual Composer Website Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 45.16.3 due to missing validation on the user-controlled 'vcv-source-id' parameter in the editor's getData AJAX action. The action loaded the post with the supplied ID and returned its title, content and page builder data without checking whether the current user was allowed to edit it. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the content of private, draft, pending and password-protected posts and pages that they are not authorized to access.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0