WordPress High · CVSS 8.8 CVE-2026-16502 September 8, 2026

Live Composer – Free WordPress Website Builder: insecure deserialization

Live Composer – Free WordPress Website Builder

Insecure deserialization in the Live Composer – Free WordPress Website Builder component. Threat level: High (CVSS 8.8).

Worried this flaw is on your site? Check it for free in under a minute, or have us fix and secure it right away.

Who is affected

This vulnerability affects: Live Composer – Free WordPress Website Builder. If you use this component on your site, check the version and update it as soon as possible.

How dangerous

Rating: High, CVSS 8.8 out of 10. It is worth acting before the flaw is exploited.

What this flaw is

Insecure deserialization processes input as ready-made objects. With a faulty implementation, this can run code or alter the application logic.

In practice it often leads to remote code execution, i.e. a site takeover.

Score breakdown (CVSS vector)

What the CVSS 8.8 rating means in practice:

  • The attack can be carried out remotely, over the internet.
  • Requires an ordinary, low-privileged account.
  • Requires no action from the victim.
  • At risk: data confidentiality, integrity (data can be altered), site availability.

Weakness class: CWE-502.

What to do

  • Update the vulnerable component (Live Composer – Free WordPress Website Builder) to the latest version.
  • If a patch is not out yet, temporarily disable the vulnerable element.
  • Check whether the site has already been attacked: unusual files, new administrator accounts, redirects.
  • Make a backup before you start making changes.
Do not guess, check

Does this flaw affect your site?

We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.

Request a free audit →

Other current WordPress threats

EDD Product Catalog Feed by PixelYourSite: security vulnerability CVE-2026-9331 · High Event Tickets and Registration: security vulnerability CVE-2026-3174 · High User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor: cross-site scripting (XSS) CVE-2026-6431 · High WP Fusion (Pro): privilege escalation CVE-2026-14444 · High See the full list →