PT-2026-84101 · WordPress · Live Composer
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Live Composer – Free WordPress Website Builder versions prior to 2.1.20
Description
Insufficient input sanitization and output escaping in the
dslc custom field shortcode allow authenticated attackers with contributor-level access or higher to perform Stored Cross-Site Scripting (XSS). This occurs when arbitrary web scripts are injected into pages, which then execute in the browser of any user who accesses the affected page.Recommendations
Update the plugin to version 2.1.20 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live Composer