Live Composer – Free WordPress Website Builder 插件(适用于 WordPress)存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,影响版本为 2.1.19 及之前所有版本。该漏洞源于对 短代码(Shortcode)的输入未充分净化,且输出未进行转义。这使得拥有贡献者(Contributor)级别或更高权限的已认证攻击者能够向页面中注入任意 Web 脚本,当用户访问这些被注入的页面时,脚本将会被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| livecomposer | Live Composer – Free WordPress Website Builder | 0 ~ 2.1.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13203 | 6.4 MEDIUM | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cu |
| CVE-2026-16788 | 6.4 MEDIUM | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dsl |
| CVE-2026-16786 | 6.4 MEDIUM | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dsl |
No comments yet