Description
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A PHP Object Injection flaw exists in the Live Composer – Free WordPress Website Builder plugin for all releases up to and including 2.1.18. The vulnerability is triggered when the plugin deserializes untrusted input provided via a shortcode. Because the flaw requires the presence of a vulnerable Plain Old PHP Object (POPO) in the running application, it does not provide immediate impact on its own. If an additional plugin or theme installed on the site contains such an object that can be abused, an attacker with contributor-level or higher rights can inject crafted payloads that may read sensitive data, delete files, or execute arbitrary code.

Affected Systems

All installations of the Live Composer Free WordPress Website Builder plugin running versions 2.1.18 or older are affected. The plugin is a WordPress extension that adds a shortcode functionality to build pages and content within the WordPress administrative interface.

Risk and Exploitability

The base CVSS score of 8.8 reflects the high severity of the vulnerability when a POPO chain exists. The EPSS score is currently not available, and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated attacker with a contributor role or higher who can submit data through the shortcode; the exploitation path depends on a second vulnerability that provides an exploitable object. Absent such a chain, the flaw has negligible impact; however, once a vulnerable POPO is present, standard PHP Object Injection techniques can result in remote code execution or other destructive actions.

Generated by OpenCVE AI on September 8, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest available update for Live Composer – Free WordPress Website Builder to remove the deserialization vulnerability
  • Audit other installed plugins and themes for objects that could serve as a POPO chain; update or remove any that pose a risk
  • Restrict contributor‑level users from interacting with the vulnerable shortcode or disable the shortcode entirely on sites that cannot be updated promptly

Generated by OpenCVE AI on September 8, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Livecomposer
Livecomposer live Composer – Free Wordpress Website Builder
Wordpress
Wordpress wordpress
Vendors & Products Livecomposer
Livecomposer live Composer – Free Wordpress Website Builder
Wordpress
Wordpress wordpress

Tue, 08 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Title Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Livecomposer Live Composer – Free Wordpress Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-08T11:29:58.916Z

Reserved: 2026-07-21T18:48:52.754Z

Link: CVE-2026-16502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T12:16:52.443

Modified: 2026-09-08T12:16:52.443

Link: CVE-2026-16502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T12:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data