PT-2026-96661 · WordPress · Live Composer

·

CVE-2026-16778

·

Published

2026-09-22

·

Updated

2026-09-30

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Live Composer – Free WordPress Website Builder versions prior to 2.1.22
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping within the dslc module downloads output shortcode content. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages. The issue arises because the wp kses post check is bypassed when the payload is stored as a serialized string. Subsequently, the shortcode callback re-emits attacker-controlled values without escaping at render time, specifically affecting the view all link (href attribute), main heading title (h2 body), button text (anchor body), and button inline svg (anchor body).
Recommendations Update Live Composer – Free WordPress Website Builder to version 2.1.22 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16778

Affected Products

Live Composer