cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlive-composer-page-builder live-composer-page-builder

Direction: ascending
Jun 07, 2024

Page Builder: Live Composer # CVE-2024-32957

CVE, Research URL

CVE-2024-32957

Date
Apr 26, 2024
Research Description
Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.
Affected versions
max 1.5.39.
Status
vulnerable

Page Builder: Live Composer # CVE-2023-52206

CVE, Research URL

CVE-2023-52206

Date
Jan 09, 2024
Research Description
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
Affected versions
max 1.5.29.
Status
vulnerable

Page Builder: Live Composer # CVE-2022-4669

CVE, Research URL

CVE-2022-4669

Date
Feb 21, 2023
Research Description
The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
max 1.5.23.
Status
vulnerable

Page Builder: Live Composer # CVE-2023-52193

CVE, Research URL

CVE-2023-52193

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.
Affected versions
max 1.5.24.
Status
vulnerable

Page Builder: Live Composer # CVE-2024-31933

CVE, Research URL

CVE-2024-31933

Date
Apr 15, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35.
Affected versions
max 1.5.36.
Status
vulnerable
Jun 21, 2024

Page Builder: Live Composer # CVE-2024-35780

CVE, Research URL

CVE-2024-35780

Date
Jun 19, 2024
Research Description
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
Affected versions
max 1.5.43.
Status
vulnerable
Jun 22, 2024

Page Builder: Live Composer # CVE-2024-35768

CVE, Research URL

CVE-2024-35768

Date
Jun 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.11.
Affected versions
max 1.5.48.
Status
vulnerable
Jul 22, 2024

Page Builder: Live Composer # CVE-2024-35779

CVE, Research URL

CVE-2024-35779

Date
Jun 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
Affected versions
max 1.5.43.
Status
vulnerable
Jan 11, 2026

Page Builder: Live Composer # CVE-2025-68598

CVE, Research URL

CVE-2025-68598

Date
Dec 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.
Affected versions
max 2.1.13.
Status
vulnerable

Page Builder: Live Composer # CVE-2025-13537

CVE, Research URL

CVE-2025-13537

Date
Dec 18, 2025
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.0.3.
Status
vulnerable

Page Builder: Live Composer # CVE-2025-14071

CVE, Research URL

CVE-2025-14071

Date
Dec 21, 2025
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Affected versions
max 2.0.3.
Status
vulnerable
Sep 02, 2026

Page Builder: Live Composer # CVE-2026-13203

CVE, Research URL

CVE-2026-13203

Date
Sep 01, 2026
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due to insufficient input sanitization and output escaping on the user-supplied attribute, which is concatenated into the HTML id="" attribute of the rendered <div> element in the dslc_modules_section_front() and dslc_modules_area_front() functions without esc_attr(). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.1.20.
Status
vulnerable

Page Builder: Live Composer # CVE-2026-16788

CVE, Research URL

CVE-2026-16788

Date
Sep 01, 2026
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's shortcode-aware kses handling preserves the serialized shortcode body as a placeholder before content filtering runs, allowing attacker-controlled values such as view_all_link, main_heading_link_title, main_filter_title_all, and button_text to reach render-time sinks entirely unescaped.
Affected versions
max 2.1.20.
Status
vulnerable

Page Builder: Live Composer # CVE-2026-16786

CVE, Research URL

CVE-2026-16786

Date
Sep 01, 2026
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload survives save-time wp_kses_post filtering because KSES treats shortcode delimiters as opaque, and the unescaped fields — including main_heading_title, view_all_link, main_heading_link_title, and main_filter_title_all — are only rendered when do_shortcode() executes at page-view time.
Affected versions
max 2.1.20.
Status
vulnerable

Page Builder: Live Composer # CVE-2026-16787

CVE, Research URL

CVE-2026-16787

Date
Sep 01, 2026
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.1.20.
Status
vulnerable
Sep 09, 2026

Page Builder: Live Composer # CVE-2026-16502

CVE, Research URL

CVE-2026-16502

Date
Sep 08, 2026
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Affected versions
max 2.1.19.
Status
vulnerable