Junglewise Threat Intelligence

CVE-2026-57754: Livemesh Addons for WPBakery Page Builder XSS in Contributor role

CVE-2026-57754 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Vendors: Livemesh.

Executive brief

Livemesh Addons for WPBakery Page Builder is a WordPress plugin used to add extra design elements and functionality to websites. A security flaw in versions 3.9.4 and earlier allows users with 'Contributor' level access to inject malicious scripts into the site. If a site administrator views the affected content, these scripts could allow an attacker to redirect visitors, display unauthorized advertisements, or potentially compromise administrative accounts.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Livemesh Addons for WPBakery Page Builder plugin for WordPress (versions <= 3.9.4). The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject malicious JavaScript into page elements. The exploit requires a victim (typically an administrator) to interact with the affected page or link. Successful exploitation allows for the execution of arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking or unauthorized site modifications. As of the advisory date, no official patch has been released.

Affected products

  • Livemesh Livemesh Addons for WPBakery Page Builder <= 3.9.4

Timeline

  • 2026-02-26: disclosed: Reported by timomangcut
  • 2026-07-02: advisory: Published by Patchstack and NVD

References