What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
Explanation of Vulnerability in Simple Terms
Live Composer Page Builder versions up to 1.5.25 contain a deserialization vulnerability in how they process untrusted data. An authenticated administrator can craft malicious serialized input that, when processed by the plugin, leads to unintended code execution or data manipulation. The vulnerability requires high-level access and complex attack conditions but can affect the entire site when exploited.
What an attacker can do
Read sensitive data or modify site content and configuration if they have admin access.
Potential impact on your site
A compromised admin account could be used to alter site data or inject malicious code via this vulnerability.
Conditions required to exploit
Attacker must have administrator-level privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities