Impact
The vulnerability exists in the Live Composer – Free WordPress Website Builder plugin, where the 'custom_id' attribute of the dslc_modules_section and dslc_modules_area shortcodes is concatenated into a div’s id attribute without sanitization. This allows an authenticated user with Contributor or higher roles to inject arbitrary scripts into pages that will execute when any user views those pages, enabling attacks such as session hijacking, cookie theft, or defacement. The weakness is a classic stored cross‑site scripting issue (CWE‑79).
Affected Systems
WordPress sites running the Live Composer plugin version 2.1.19 or earlier are affected. All installations of this plugin that have not been updated to a newer release are vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector requires authenticated Contributor-level access, meaning attackers who have been granted these credentials can exploit the flaw readily. Given the potential for widespread script execution on all users of the affected site, the risk remains significant and mitigation should be prioritized.
OpenCVE Enrichment