Page Builder: Live Composer
Page Builder: Live Composer builds WordPress pages visually with drag-and-drop content elements and live frontend editing.
Page Builder: Live Composer (live-composer-page-builder) is a WordPress plugin with 15 published CVE records in this archive. The latest tracked vulnerability was published Sep 08, 2026; the highest published CVSS base score is 8.8.
live-composer-page-builderCVE-2026-16502: Live Composer permits contributor-level PHP object injection
Live Composer through 2.1.18 deserializes untrusted input, allowing a Contributor or higher-privileged user to inject PHP objects. The advisory reports no known usable object gadget chain in Live Composer itself; file deletion, data disclosure, or code execution requires a suitable chain in another installed plugin or theme. The official changelog confirms the PHP object injection fix in 2.1.19.
| Safe version |
|
||
|---|---|---|---|
| Sep 08, 2026 |
CVE-2026-16502
Live Composer permits contributor-level PHP object injection
Live Composer through 2.1.18 deserializes untrusted input, allowing a Contributor or higher-privileged user to inject PHP objects. The advisory reports no known usable object gadget chain in Live Composer itself; file deletion, data disclosure, or code execution requires a suitable chain in another installed plugin or theme. The official changelog confirms the PHP object injection fix in 2.1.19.
|
2.1.19 |
CVE8.8
NVDPending
|
| Sep 01, 2026 |
CVE-2026-16788
Live Composer project shortcodes permit Contributor-level stored cross-site scripting
Live Composer through 2.1.19 preserves the serialized body of dslc_module_projects_output as a shortcode placeholder while content filtering runs. A Contributor or higher can therefore carry values such as view_all_link, main_heading_link_title, main_filter_title_all, and button_text through save-time filtering into unescaped render-time sinks, causing stored script to execute when the page is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 01, 2026 |
CVE-2026-16786
Live Composer testimonial shortcodes permit Contributor-level stored cross-site scripting
Live Composer through 2.1.19 treats the dslc_module_testimonials_output shortcode body as opaque during save-time filtering. A Contributor or higher can store malicious values in fields including main_heading_title, view_all_link, main_heading_link_title, and main_filter_title_all; do_shortcode() later renders those values without adequate escaping and executes the script when the page is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 01, 2026 |
CVE-2026-16787
Live Composer custom-field shortcode permits stored cross-site scripting
Live Composer through 2.1.19 insufficiently sanitizes and escapes values rendered by the dslc_custom_field shortcode. A Contributor or higher can store script that executes when another user views the affected page.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 01, 2026 |
CVE-2026-13203
Live Composer custom ID attributes permit stored cross-site scripting
Live Composer through 2.1.19 concatenates the custom_id attribute from dslc_modules_section and dslc_modules_area shortcodes into a rendered div id without esc_attr() in dslc_modules_section_front() and dslc_modules_area_front(). A Contributor or higher can break out of the attribute and store script that executes when another user views the page.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68598
Page Builder: Live Composer: Cross-site scripting
Page Builder: Live Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 21, 2025 |
CVE-2025-14071
Live Composer – Free WordPress Website Builder: Code execution
Live Composer – Free WordPress Website Builder is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Dec 17, 2025 |
CVE-2025-13537
Live Composer – Free WordPress Website Builder: Cross-site scripting
Live Composer – Free WordPress Website Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 21, 2024 |
CVE-2024-35768
Page Builder: Live Composer: Cross-site scripting
Page Builder: Live Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Jun 21, 2024 |
CVE-2024-35779
Page Builder: Live Composer: Cross-site scripting
Page Builder: Live Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 19, 2024 |
CVE-2024-35780
Page Builder: Live Composer: Code execution
Page Builder: Live Composer is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Apr 26, 2024 |
CVE-2024-32957
Page Builder: Live Composer: A security weakness
Page Builder: Live Composer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.7
NVDPending
|
| Apr 15, 2024 |
CVE-2024-31933
Page Builder: Live Composer: Cross-site request forgery
Page Builder: Live Composer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 01, 2024 |
CVE-2023-52193
Page Builder: Live Composer: Cross-site scripting
Page Builder: Live Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jan 08, 2024 |
CVE-2023-52206
Page Builder: Live Composer: Code execution
Page Builder: Live Composer is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.7
NVD7.2
|