cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlive-composer-page-builder live-composer-page-builder

Direction: ascending
Jun 07, 2024

Page Builder: Live Composer # CVE-2024-32957

CVE, Research URL

CVE-2024-32957

Date
Apr 26, 2024
Research Description
Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.
Affected versions
max 1.5.39.
Status
vulnerable

Page Builder: Live Composer # CVE-2023-52206

CVE, Research URL

CVE-2023-52206

Date
Jan 09, 2024
Research Description
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
Affected versions
max 1.5.29.
Status
vulnerable

Page Builder: Live Composer # CVE-2022-4669

CVE, Research URL

CVE-2022-4669

Date
Feb 21, 2023
Research Description
The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
max 1.5.23.
Status
vulnerable

Page Builder: Live Composer # CVE-2023-52193

CVE, Research URL

CVE-2023-52193

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.
Affected versions
max 1.5.24.
Status
vulnerable

Page Builder: Live Composer # CVE-2024-31933

CVE, Research URL

CVE-2024-31933

Date
Apr 15, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35.
Affected versions
max 1.5.36.
Status
vulnerable
Jun 21, 2024

Page Builder: Live Composer # CVE-2024-35780

CVE, Research URL

CVE-2024-35780

Date
Jun 19, 2024
Research Description
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
Affected versions
max 1.5.43.
Status
vulnerable
Jun 22, 2024

Page Builder: Live Composer # CVE-2024-35768

CVE, Research URL

CVE-2024-35768

Date
Jun 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
Affected versions
max 1.5.44.
Status
vulnerable
Jul 22, 2024

Page Builder: Live Composer # CVE-2024-35779

CVE, Research URL

CVE-2024-35779

Date
Jun 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.
Affected versions
max 1.5.43.
Status
vulnerable
Jan 11, 2026

Page Builder: Live Composer # CVE-2025-68598

CVE, Research URL

CVE-2025-68598

Date
Dec 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.0.5.
Affected versions
max 2.0.5.
Status
vulnerable

Page Builder: Live Composer # CVE-2025-13537

CVE, Research URL

CVE-2025-13537

Date
Dec 18, 2025
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.0.3.
Status
vulnerable

Page Builder: Live Composer # CVE-2025-14071

CVE, Research URL

CVE-2025-14071

Date
Dec 21, 2025
Research Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Affected versions
max 2.0.3.
Status
vulnerable