Visual Composer Website Builder <= 45.16.3 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via 'vcv-source-id' Parameter
- ID
- WPSEC-2026-0632
- Plugin
- Visual Composer Website Builder (visualcomposer)
- Affected
- all versions before 45.16.4
- Remediation
- Update to 45.16.4 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Visual Composer Website Builder on WPSec AttackSurface
- Fix released
- Published
Description
The Visual Composer Website Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 45.16.3 due to missing validation on the user-controlled 'vcv-source-id' parameter in the editor's getData AJAX action. The action loaded the post with the supplied ID and returned its title, content and page builder data without checking whether the current user was allowed to edit it. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the content of private, draft, pending and password-protected posts and pages that they are not authorized to access.
References
- https://wpsec.com/vuln/WPSEC-2026-0632/
- https://plugins.svn.wordpress.org/visualcomposer/tags/45.16.4/
- https://wordpress.org/plugins/visualcomposer/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS