Executive brief
Livemesh Addons for Elementor is a WordPress plugin that provides additional design elements and widgets for the Elementor page builder. A security vulnerability in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into website pages. If a site administrator or visitor views the affected page, the script could execute, potentially leading to unauthorized actions, data theft, or redirection to malicious websites.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Livemesh Addons for Elementor plugin for WordPress due to improper neutralization of user input during web page generation. The flaw allows an authenticated attacker with 'Contributor' or higher privileges to inject malicious JavaScript payloads into the site's database via plugin-provided widgets or settings. Because the input is not properly sanitized before being rendered on the front-end, the script executes in the context of any user (including administrators) who views the compromised page. This can lead to session hijacking, unauthorized administrative actions, or site defacement. The vulnerability affects all versions up to and including 9.0; as of the advisory date, no official patch has been confirmed.
Affected products
- livemesh Livemesh Addons for Elementor <= 9.0
Timeline
- 2026-01-14: other: Vulnerability reported by researcher Jitlada
- 2026-02-13: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD