CVE-2026-16786 | LiveComposer Live Composer Plugin up to 2.1.19 on WordPress Shortcode do_shortcode cross site scripting
A vulnerability was found in LiveComposer Live Composer Plugin up to 2.1.19 on WordPress. It has been classified as problematic. Affected by this issue is the function do_shortcode of the component Shortcode Handler. Performing a manipulation of the argument main_heading_title/view_all_link/main_heading_link_title/main_filter_title_all results in cross site scripting.
This vulnerability was named CVE-2026-16786. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More