Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the Live Composer – Free WordPress Website Builder plugin. The flaw is triggered by the 'dslc_custom_field' shortcode, which inadequately sanitizes input and fails to escape output. As a result, a malicious contributor or higher can inject JavaScript into a page that will run whenever any user visits that page, potentially allowing session hijacking, defacement, or data theft. The weakness is a classic input validation failure, reflected in CWE‑79.
Affected Systems
All installations of the Live Composer plugin with versions 2.1.19 or earlier are affected. The plugin is identified by the vendor name Live Composer – Free WordPress Website Builder. Users should verify the exact version of the plugin installed on their WordPress sites.
Risk and Exploitability
The reported CVSS score of 6.4 indicates a moderate level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not a known, actively exploited vulnerability at the time of analysis. However, because the flaw is user‑controllable and can be leveraged by any authenticated contributor or higher, the likelihood of exploitation in environments where such roles are granted remains significant. The attack vector is authenticated; an attacker must have access to the WordPress administration interface with at least contributor level, but no extra network or privilege escalation is required to inject the payload, making remediation a priority.
OpenCVE Enrichment