Junglewise Threat Intelligence

CVE-2026-2030: Livemesh WPBakery Page Builder Addons Stored XSS in Carousel Shortcodes

CVE-2026-2030 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Livemesh.

Executive brief

The WPBakery Page Builder Addons by Livemesh plugin for WordPress, which provides additional design elements for website building, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcodes. Specifically, shortcode attributes are processed using `wp_json_encode()` and placed into single-quoted `data-settings` HTML attributes without the use of `esc_attr()`. This allows an authenticated attacker with Contributor-level permissions or higher to break out of the HTML attribute by injecting single quotes and execute arbitrary JavaScript in the context of a user's browser. The vulnerability affects all versions up to and including 3.9.4.

Affected products

  • Livemesh WPBakery Page Builder Addons by Livemesh Up to, and including, 3.9.4

Timeline

  • 2026-05-27: disclosed: Vulnerability published to NVD
  • 2026-05-27: advisory: Wordfence advisory published

References

Related threats