CVE-2026-65568
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-65568 is a Broken Access Control vulnerability (Missing Authorization) in the Visual Composer Website Builder WordPress plugin affecting versions 45.15.0 and earlier. It allows authenticated users with contributor-level privileges to perform unauthorized actions beyond their intended permission scope. The vulnerability was published on July 27, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.0 (Medium) (GitHub Advisory, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks when a contributor-level user attempts to access or modify resources beyond their permitted scope. An authenticated attacker with contributor privileges can exploit this over the network with low attack complexity and no user interaction required, resulting in unauthorized content or settings modifications. The scope is marked as Changed, indicating the impact extends beyond the vulnerable component itself (GitHub Advisory).

Impact

Successful exploitation allows an authenticated contributor to modify website content or settings beyond their intended authorization scope through the Visual Composer Website Builder interface. The primary impact is on integrity (low), with no confidentiality or availability impact. While the individual impact is limited, unauthorized content modification could be leveraged for defacement, injection of malicious content, or privilege escalation within the WordPress site context (GitHub Advisory, Patchstack).

Mitigation and workarounds

Update the Visual Composer Website Builder plugin to a version newer than 45.15.0, as a patch has been made available per GitHub Advisory GHSA-8pw6-rj96-2r94. As interim measures, administrators should review and audit contributor account permissions, restrict contributor access to only the specific pages or post types they need to manage, and monitor for unexpected content changes. No specific workaround bypassing the need to update has been documented (GitHub Advisory, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65562MEDIUM6.5
  • betterdocs
NoYesJul 27, 2026
CVE-2026-65563MEDIUM5.9
  • themeisle-companion
NoYesJul 27, 2026
CVE-2026-65557MEDIUM5.9
  • woocommerce-abandoned-cart
NoYesJul 27, 2026
CVE-2026-65567MEDIUM5.3
  • event-tickets
NoYesJul 27, 2026
CVE-2026-65568MEDIUM5
  • visualcomposer
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management