# Visual Composer Website Builder <= 45.16.3 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via 'vcv-source-id' Parameter

- **ID:** WPSEC-2026-0632
- **Plugin:** Visual Composer Website Builder (`visualcomposer`), https://wordpress.org/plugins/visualcomposer/
- **Affected versions:** all versions before 45.16.4
- **Fixed in:** 45.16.4 (Update to 45.16.4 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/visualcomposer
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0632/

## Description

The Visual Composer Website Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 45.16.3 due to missing validation on the user-controlled 'vcv-source-id' parameter in the editor's getData AJAX action. The action loaded the post with the supplied ID and returned its title, content and page builder data without checking whether the current user was allowed to edit it. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the content of private, draft, pending and password-protected posts and pages that they are not authorized to access.

## References

- https://wpsec.com/vuln/WPSEC-2026-0632/
- https://plugins.svn.wordpress.org/visualcomposer/tags/45.16.4/
- https://wordpress.org/plugins/visualcomposer/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0632/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
