Input validation vulnerability in Visual Composer Website Builder 45.11.0

The Visual Composer Website Builder is a plugin for WordPress that is not safe from a security issue called Stored Cross-Site Scripting. This means that hackers can use it to insert harmful code into web pages. This can happen in any version up to 45.11.0 of the plugin because it does not properly filter and clean the information entered and displayed. This can be done by someone who has access to contribute to the website and above.

Detected in:

Visual Composer Website Builder fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.