Impact
The vulnerability is a stored cross‑site scripting flaw located in the dslc_module_projects_output shortcode of the Live Composer – Free WordPress Website Builder plugin. The flaw arises from insufficient sanitization of user‑supplied shortcode parameters such as view_all_link, main_heading_link_title, and button_text, allowing attacker‑controlled script payloads to be stored and then rendered unescaped when a page is viewed. This result is the execution of malicious code in the browsers of any user who visits a page containing the injected shortcode content.
Affected Systems
Affected systems are WordPress installations that have the Live Composer plugin installed in any version up to and including 2.1.19. The plugin is supplied by the vendor livecomposer under the name Live Composer – Free WordPress Website Builder. No specific operating system or WordPress core version is mentioned; the flaw is limited to the plugin code.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate to high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires authenticated access with contributor‑level or higher privileges. An attacker can create or edit shortcode content with malicious script, which will then execute for all users who view the affected page. Because stored XSS can impact a large number of site visitors, the risk is significant, especially on high‑traffic sites.
OpenCVE Enrichment