← العودة للجدول
CVE-2026-16787
CVE-2026-16787 — The Live Composer – Free WordPress Website Builder plugin for WordPress is vul
📅 2026-09-01
🟡 Medium 🔥 No NVD Vulnerability WordPress CVSS 6.4

📋 الوصف الكامل

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-16787

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.1.19

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←