PT-2026-96661 · WordPress · Live Composer
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Live Composer – Free WordPress Website Builder versions prior to 2.1.22
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping within the
dslc module downloads output shortcode content. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages. The issue arises because the wp kses post check is bypassed when the payload is stored as a serialized string. Subsequently, the shortcode callback re-emits attacker-controlled values without escaping at render time, specifically affecting the view all link (href attribute), main heading title (h2 body), button text (anchor body), and button inline svg (anchor body).Recommendations
Update Live Composer – Free WordPress Website Builder to version 2.1.22 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live Composer