Stored Cross-Site Scripting Vulnerability in Live Composer Plugin for WordPress
CVE-2026-13203
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-13203?
The Live Composer β Free WordPress Website Builder plugin exhibits a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the 'custom_id' shortcode attribute. This vulnerability arises from inadequate input sanitization and output escaping, enabling malicious scripts to be embedded into the id attribute of rendered HTML elements. As a result, when users visit an affected page, these scripts execute, potentially compromising user sessions and data.
Affected Version(s)
Live Composer β Free WordPress Website Builder 0 <= 2.1.19