Vulnerabilities and security researches forlive-composer-page-builder live-composer-page-builder
Direction: ascendingJun 07, 2024
Page Builder: Live Composer # CVE-2024-32957
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 26, 2024
- Research Description
- Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.
- Affected versions
-
max 1.5.39.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2023-52206
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 09, 2024
- Research Description
- Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
- Affected versions
-
max 1.5.29.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2022-4669
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 21, 2023
- Research Description
- The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected versions
-
max 1.5.23.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2023-52193
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.
- Affected versions
-
max 1.5.24.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2024-31933
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 15, 2024
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35.
- Affected versions
-
max 1.5.36.
- Status
-
vulnerable
Jun 21, 2024
Page Builder: Live Composer # CVE-2024-35780
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 19, 2024
- Research Description
- Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
- Affected versions
-
max 1.5.43.
- Status
-
vulnerable
Jun 22, 2024
Page Builder: Live Composer # CVE-2024-35768
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 21, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.11.
- Affected versions
-
max 1.5.48.
- Status
-
vulnerable
Jul 22, 2024
Page Builder: Live Composer # CVE-2024-35779
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 21, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
- Affected versions
-
max 1.5.43.
- Status
-
vulnerable
Jan 11, 2026
Page Builder: Live Composer # CVE-2025-68598
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 24, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.
- Affected versions
-
max 2.1.13.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2025-13537
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 18, 2025
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.0.3.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2025-14071
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 21, 2025
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
- Affected versions
-
max 2.0.3.
- Status
-
vulnerable
Sep 02, 2026
Page Builder: Live Composer # CVE-2026-13203
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 01, 2026
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due to insufficient input sanitization and output escaping on the user-supplied attribute, which is concatenated into the HTML id="" attribute of the rendered <div> element in the dslc_modules_section_front() and dslc_modules_area_front() functions without esc_attr(). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.1.20.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2026-16788
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 01, 2026
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's shortcode-aware kses handling preserves the serialized shortcode body as a placeholder before content filtering runs, allowing attacker-controlled values such as view_all_link, main_heading_link_title, main_filter_title_all, and button_text to reach render-time sinks entirely unescaped.
- Affected versions
-
max 2.1.20.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2026-16786
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 01, 2026
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload survives save-time wp_kses_post filtering because KSES treats shortcode delimiters as opaque, and the unescaped fields — including main_heading_title, view_all_link, main_heading_link_title, and main_filter_title_all — are only rendered when do_shortcode() executes at page-view time.
- Affected versions
-
max 2.1.20.
- Status
-
vulnerable
Page Builder: Live Composer # CVE-2026-16787
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 01, 2026
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.1.20.
- Status
-
vulnerable
Sep 09, 2026
Page Builder: Live Composer # CVE-2026-16502
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 08, 2026
- Research Description
- The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
- Affected versions
-
max 2.1.19.
- Status
-
vulnerable