CVE-2026-45436: WordPress WPBakery Page Builder plugin <= 8.7.2 - Broken Access Control vulnerability
Published Jun 17, 2026
·Updated
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
Affected Software
1 affected component
wpbakery WPBakery Page Builder<=8.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPBakery Page Builder pluginto a version that resolves this vulnerability.Fixed in 8.7.3
Event History
Jun 17, 2026
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45436?
The severity of CVE-2026-45436 is classified as medium with a score of 6.5.
2
How do I fix CVE-2026-45436?
To fix CVE-2026-45436, update the WPBakery Page Builder plugin to version 8.7.3 or later.
3
What type of vulnerability is CVE-2026-45436?
CVE-2026-45436 is a Broken Access Control vulnerability that affects subscribers in WPBakery Page Builder.
4
Which versions of WPBakery Page Builder are affected by CVE-2026-45436?
CVE-2026-45436 affects all versions of WPBakery Page Builder up to and including version 8.7.2.
5
What impact does CVE-2026-45436 have on users?
CVE-2026-45436 can allow unauthorized access for subscribers to perform actions not intended for their role on the site.