Junglewise Threat Intelligence

CVE-2025-68598: Live Composer Page Builder stored cross-site scripting

CVE-2025-68598 · Severity: medium · CVSS 6.5 · Published 2025-12-24

Executive brief

Live Composer is a popular WordPress page builder plugin that allows website administrators to design and edit pages visually. A stored cross-site scripting (XSS) vulnerability in versions up to 2.1.22 allows authenticated users with contributor or developer privileges to inject malicious scripts into pages. When other users view these pages, the scripts execute in their browsers, potentially stealing session data, account credentials, or hijacking user actions.

Technical details

The vulnerability is a stored XSS flaw in the Live Composer page builder plugin affecting versions through 2.1.22. It arises from improper neutralization of user input during web page generation, allowing authenticated users with contributor or developer-level privileges to inject malicious JavaScript into page content. The injected scripts are stored in the database and executed in the browsers of all subsequent visitors, including administrators. Attack requires user interaction—the injected script executes only when a victim visits the compromised page. No official patch is currently available.

Affected products

  • Live Composer Team Page Builder: Live Composer through 2.1.22

Timeline

  • 2025-12-22: disclosed
  • 2025-12-24: advisory: NVD published

References