Stored Cross-Site Scripting in Livemesh Addons for Beaver Builder Plugin by WordPress
CVE-2026-2029
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 February 2026
What is CVE-2026-2029?
The Livemesh Addons for Beaver Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises from the improper handling of input attributes in the [labb_pricing_item] shortcode, specifically the title and value fields. The plugin fails to appropriately sanitize and escape user input, allowing authenticated users, such as those with Contributor-level access, to inject malicious scripts. When a page containing the compromised items is accessed, these scripts execute in the context of the user’s session, potentially leading to security breaches and data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Livemesh Addons for Beaver Builder * <= 3.9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved