Junglewise Threat Intelligence

CVE-2026-3895: Livemesh WPBakery Page Builder Addons Stored XSS in lvca_admin_ajax

CVE-2026-3895 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Livemesh.

Executive brief

A popular WordPress plugin used to add features to the WPBakery Page Builder contains a security flaw that allows low-level users to inject malicious scripts into the website. This could allow an attacker to hijack administrator sessions or redirect visitors to malicious websites. The issue stems from a failure to properly check user permissions when saving plugin settings.

Technical details

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'lvca_admin_ajax' AJAX action. The vulnerability exists in versions up to and including 3.9.4 because the AJAX handler performs a nonce check but fails to verify user capabilities (missing authorization). This allows authenticated attackers with Subscriber-level permissions or higher to modify plugin settings and inject arbitrary web scripts. These scripts are then stored and executed in the browser of any user, including administrators, who visits the affected settings page or the site's frontend.

Affected products

  • Livemesh WPBakery Page Builder Addons by Livemesh Up to, and including, 3.9.4

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats