Impact
The vulnerability occurs when the dslc_module_testimonials_output shortcode renders unescaped user‑supplied fields such as main_heading_title, view_all_link, main_heading_link_title, and main_filter_title_all. An authenticated contributor or higher can inject arbitrary scripts that survive the wp_kses_post filter because shortcode syntax is treated as opaque. When any visitor loads a page containing the module, the embedded script runs in the victim’s browser, enabling cookie theft, content defacement, or phishing attacks.
Affected Systems
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable in all releases through 2.1.19. WordPress sites running any of those versions are affected.
Risk and Exploitability
The CVSS v3.1 base score is 6.4, indicating a medium severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the Contributor role level or higher, but the stored nature of the payload means that any visitor to a compromised page becomes a victim, giving the attacker broad impact without further effort.
OpenCVE Enrichment