CVE-2025-68598: WordPress Page Builder: Live Composer plugin <= 2.1.13 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68598?
CVE-2025-68598 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-68598?
To fix CVE-2025-68598, you should update Live Composer Page Builder to version 2.0.6 or later.
Who is affected by CVE-2025-68598?
Users of Live Composer Page Builder versions from n/a through 2.0.5 are affected by CVE-2025-68598.
What type of vulnerability is CVE-2025-68598?
CVE-2025-68598 is a cross-site scripting (XSS) vulnerability resulting from improper neutralization of input during web page generation.
Can CVE-2025-68598 lead to data theft?
Yes, CVE-2025-68598 can lead to data theft by allowing an attacker to execute malicious scripts in the context of the victim's browser.