Stored Cross-Site Scripting Vulnerability in Live Composer Plugin for WordPress
CVE-2026-16788
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-16788?
The Live Composer plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in its dslc_module_projects_output Shortcode. This vulnerability affects all versions up to and including 2.1.19. Authenticated attackers with contributor-level access or higher can exploit this flaw by injecting malicious web scripts into pages. Once injected, these scripts execute whenever a user accesses affected pages, leading to potential data compromise or phishing attacks. The plugin's handling of shortcode processing fails to sufficiently sanitize user inputs, allowing attacker-controlled values to bypass security measures.
Affected Version(s)
Live Composer β Free WordPress Website Builder 0 <= 2.1.19