Known vulnerabilities in Visual Composer Website Builder
Drag and drop page builder that gives the freedom to design WordPress websites, landing pages, custom themes, maintenance mode & coming soon pages.
6Reported vulnerabilities
6.4Highest CVSS score
45.16.1Latest version
40,000+Active installs
What to do now
Update Visual Composer Website Builder to 45.16.0 or later.
6 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-55709 | Medium | 0.2% | 45.13.0 and earlier | 45.15.0 |
August 14, 2025 |
| CVE-2025-48276 | Medium | 0.2% | 45.11.0 and earlier | 45.12.0 |
May 19, 2025 |
| CVE-2025-46254 | Medium | 0.2% | 45.10.0 and earlier | 45.11.0 |
April 22, 2025 |
| CVE-2024-35653 | Medium | 0.3% | 45.8.0 and earlier | 45.9.0 |
June 3, 2024 |
| CVE-2024-27997 | Medium | 0.3% | 45.6.0 and earlier | 45.7.0 |
March 15, 2024 |
| CVE-2026-65568 | Medium | 0.2% | 45.15.0 and earlier | 45.16.0 |
July 24, 2026 |