{
 "id": "WPSEC-2026-0632",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0632/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0632/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0632/index.md",
 "title": "Visual Composer Website Builder <= 45.16.3 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via 'vcv-source-id' Parameter",
 "description": "The Visual Composer Website Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 45.16.3 due to missing validation on the user-controlled 'vcv-source-id' parameter in the editor's getData AJAX action. The action loaded the post with the supplied ID and returned its title, content and page builder data without checking whether the current user was allowed to edit it. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the content of private, draft, pending and password-protected posts and pages that they are not authorized to access.",
 "plugin": {
  "slug": "visualcomposer",
  "name": "Visual Composer Website Builder",
  "full_name": "Visual Composer Website Builder",
  "wordpress_org": "https://wordpress.org/plugins/visualcomposer/",
  "advisories_url": "https://wpsec.com/vuln/plugin/visualcomposer/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/visualcomposer"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "45.16.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 45.16.4"
  ]
 },
 "introduced_in": null,
 "fixed_in": "45.16.4",
 "remediation": "Update to 45.16.4 or later.",
 "fix_released": "2026-10-07T09:40:18+00:00",
 "published": "2026-10-08T09:45:16+00:00",
 "updated": "2026-10-07T12:20:01.658025+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0632/",
  "https://plugins.svn.wordpress.org/visualcomposer/tags/45.16.4/",
  "https://wordpress.org/plugins/visualcomposer/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/visualcomposer",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-08"
 }
}