<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Live Composer - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/live-composer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 13:40:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/live-composer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection in Live Composer WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-16502-live-composer/</link><pubDate>Tue, 08 Sep 2026 13:40:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-16502-live-composer/</guid><description>The Live Composer plugin for WordPress (&lt;= 2.1.18) contains a PHP object injection vulnerability that allows authenticated contributors to achieve remote code execution if a compatible POP chain exists in the environment.</description><content:encoded><![CDATA[<p>The Live Composer - Free WordPress Website Builder plugin for WordPress, in versions up to and including 2.1.18, is susceptible to a PHP Object Injection vulnerability. This flaw stems from the insecure deserialization of untrusted input handled by the plugin. While the Live Composer codebase itself does not contain a Property-Oriented Programming (POP) chain, the vulnerability can be leveraged if other plugins or themes installed on the same WordPress instance provide a usable POP chain. An attacker with contributor-level privileges or higher can trigger the deserialization process. Depending on the available POP chain, successful exploitation may result in unauthorized file deletion, information disclosure, or remote code execution. This vulnerability requires an initial foothold in the form of authenticated access, making it a risk primarily in multi-user WordPress environments where low-privileged users have access to the dashboard.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 8.8, reflecting its potential for severe impact, including remote code execution. Targets include any WordPress site running the vulnerable Live Composer plugin version 2.1.18 or earlier. The actual impact is environment-dependent, relying on the presence of secondary software that provides the necessary gadgets for a POP chain, which may be commonly found in feature-rich WordPress ecosystems.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the Live Composer - Free WordPress Website Builder plugin to the latest available version beyond 2.1.18.</li>
<li>Perform an audit of installed WordPress plugins and themes to identify and remove unused components that may contain known gadget chains (POP chains).</li>
<li>Restrict administrative and contributor access to the WordPress dashboard to trusted users to prevent the exploitation of this and similar authenticated vulnerabilities.</li>
<li>Implement a Web Application Firewall (WAF) to monitor for malicious serialized PHP objects being passed via HTTP request parameters.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>