Stored Cross-Site Scripting Vulnerability in Live Composer WordPress Plugin
CVE-2026-16786

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 September 2026

What is CVE-2026-16786?

The Live Composer plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitation and output escaping within the dslc_module_testimonials_output Shortcode. This vulnerability affects all versions up to and including 2.1.19, allowing authenticated users with contributor-level access and above to inject arbitrary JavaScript payloads. These payloads can execute on pages accessed by users where the vulnerable attributes—such as main_heading_title and view_all_link—are rendered. The filtering mechanism, wp_kses_post, fails to adequately sanitize the input during save-time, thereby allowing malicious scripts to persist and execute during page loads.

Affected Version(s)

Live Composer – Free WordPress Website Builder 0 <= 2.1.19

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.