← العودة للجدول
CVE-2026-13203
CVE-2026-13203 — The Live Composer – Free WordPress Website Builder plugin for WordPress is vul
📅 2026-09-01
🟡 Medium 🔥 No NVD Exploit WordPress CVSS 6.4

📋 الوصف الكامل

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due to insufficient input sanitization and output escaping on the user-supplied attribute, which is concatenated into th

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-13203

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.1.19

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←