CVE-2024-35768
Executive Summary
CVE-2024-35768 exposes a DOM‑based XSS flaw in the Live Composer Page Builder WordPress plugin. The vulnerability allows attackers to inject malicious scripts into pages generated by the plugin, potentially enabling session hijacking, defacement, or credential theft. It affects all releases up to 2.1.22 and is not yet listed in CISA KEV. Immediate patching or disabling the plugin is recommended.
Authoritative CVE Metadata - CVSS Base Score: 5.9 (MEDIUM) - Published: 2024-06-21T13:15:11.460 - Last Modified: 2026-09-21T11:17:05.783
Original Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22.
"Do not turn back when you are just at the goal."
— Publilius Syrus