Executive brief
A popular WordPress plugin used to add features to the WPBakery Page Builder contains a security flaw that allows low-level users to inject malicious scripts into the website. This could allow an attacker to hijack administrator sessions or redirect visitors to malicious websites. The issue stems from a failure to properly check user permissions when saving plugin settings.
Technical details
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'lvca_admin_ajax' AJAX action. The vulnerability exists in versions up to and including 3.9.4 because the AJAX handler performs a nonce check but fails to verify user capabilities (missing authorization). This allows authenticated attackers with Subscriber-level permissions or higher to modify plugin settings and inject arbitrary web scripts. These scripts are then stored and executed in the browser of any user, including administrators, who visits the affected settings page or the site's frontend.
Affected products
- Livemesh WPBakery Page Builder Addons by Livemesh Up to, and including, 3.9.4
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
References
- https://plugins.trac.wordpress.org/browser/addons-for-visual-composer/tags/3.9.4/admin/admin-ajax.php
- https://plugins.trac.wordpress.org/browser/addons-for-visual-composer/tags/3.9.4/admin/views/settings.php
- https://plugins.trac.wordpress.org/browser/addons-for-visual-composer/tags/3.9.4/includes/helper-functions.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ff0d4000-020b-4e22-9362-a8f0f5df321e?source=cve