Stored Cross-Site Scripting Vulnerability in Live Composer WordPress Plugin
CVE-2026-16786
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-16786?
The Live Composer plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitation and output escaping within the dslc_module_testimonials_output Shortcode. This vulnerability affects all versions up to and including 2.1.19, allowing authenticated users with contributor-level access and above to inject arbitrary JavaScript payloads. These payloads can execute on pages accessed by users where the vulnerable attributes—such as main_heading_title and view_all_link—are rendered. The filtering mechanism, wp_kses_post, fails to adequately sanitize the input during save-time, thereby allowing malicious scripts to persist and execute during page loads.
Affected Version(s)
Live Composer – Free WordPress Website Builder 0 <= 2.1.19