Page Builder: Live Composer Stored Cross-Site Scripting Vulnerability (CVE-2022-4669) — Medium Severity

WordPress is a powerful platform, and plugins like “Page Builder: Live Composer” help users create stunning websites easily. However, even useful tools can sometimes have security weaknesses. This post will break down a notable security flaw found in the Page Builder: Live Composer WordPress plugin, identified as CVE-2022-4669.

This vulnerability is a type of attack called Stored Cross-Site Scripting (XSS). In simple terms, this means that a malicious script can be permanently injected into a website. When other users visit the compromised page, their browsers execute this script without them knowing, potentially leading to unauthorized actions, data theft, or defacement of the website. For this particular flaw, users with at least a Contributor role on the WordPress site could take advantage of it.

CVE Details

  • Product Name: Page Builder: Live Composer WordPress plugin
  • Published Date: February 21, 2023
  • Last Modified: February 27, 2026
  • Status: Analyzed

Affected Products

The Page Builder: Live Composer WordPress plugin versions before 1.5.23 are vulnerable to this issue. If you are running an older version, your website could be at risk.

Current Status

This vulnerability has been officially “Analyzed,” meaning its details have been thoroughly investigated and recorded in security databases.

Severity Level

The CVE-2022-4669 vulnerability is rated as Medium severity, with a CVSS score of 5.4. A medium rating indicates that while the vulnerability isn’t critical, it can still lead to significant impacts if exploited. In this case, an attacker could inject harmful scripts that run in the browsers of other users, potentially compromising their sessions or defacing website content.

Possible Solutions

The good news is that a fix for this vulnerability is available. Users of the Page Builder: Live Composer plugin should update their installations to version 1.5.23 or newer immediately. Updating your plugins is a critical step in maintaining the security of your WordPress site and helps protect against known vulnerabilities like this one.

References

  • https://wpscan.com/vulnerability/79f011e4-3422-4307-8736-f27048796aae
  • https://wpscan.com/vulnerability/79f011e4-3422-4307-8736-f27048796aae

Suggested Internal Backlinks:

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.