{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/live-composer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:live_composer:live_composer:*:*:*:*:free:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16502"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Live Composer – Free WordPress Website Builder (\u003c= 2.1.18)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Live Composer"],"content_html":"\u003cp\u003eThe Live Composer - Free WordPress Website Builder plugin for WordPress, in versions up to and including 2.1.18, is susceptible to a PHP Object Injection vulnerability. This flaw stems from the insecure deserialization of untrusted input handled by the plugin. While the Live Composer codebase itself does not contain a Property-Oriented Programming (POP) chain, the vulnerability can be leveraged if other plugins or themes installed on the same WordPress instance provide a usable POP chain. An attacker with contributor-level privileges or higher can trigger the deserialization process. Depending on the available POP chain, successful exploitation may result in unauthorized file deletion, information disclosure, or remote code execution. This vulnerability requires an initial foothold in the form of authenticated access, making it a risk primarily in multi-user WordPress environments where low-privileged users have access to the dashboard.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 8.8, reflecting its potential for severe impact, including remote code execution. Targets include any WordPress site running the vulnerable Live Composer plugin version 2.1.18 or earlier. The actual impact is environment-dependent, relying on the presence of secondary software that provides the necessary gadgets for a POP chain, which may be commonly found in feature-rich WordPress ecosystems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the Live Composer - Free WordPress Website Builder plugin to the latest available version beyond 2.1.18.\u003c/li\u003e\n\u003cli\u003ePerform an audit of installed WordPress plugins and themes to identify and remove unused components that may contain known gadget chains (POP chains).\u003c/li\u003e\n\u003cli\u003eRestrict administrative and contributor access to the WordPress dashboard to trusted users to prevent the exploitation of this and similar authenticated vulnerabilities.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to monitor for malicious serialized PHP objects being passed via HTTP request parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T13:40:41Z","date_published":"2026-09-08T13:40:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-16502-live-composer/","summary":"The Live Composer plugin for WordPress (\u003c= 2.1.18) contains a PHP object injection vulnerability that allows authenticated contributors to achieve remote code execution if a compatible POP chain exists in the environment.","title":"PHP Object Injection in Live Composer WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-16502-live-composer/"}],"language":"en","title":"CraftedSignal Threat Feed - Live Composer","version":"https://jsonfeed.org/version/1.1"}