Stored Cross-Site Scripting Vulnerability in WPBakery Page Builder Addons by Livemesh
CVE-2026-2030
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-2030?
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is subjected to a Stored Cross-Site Scripting vulnerability due to improper input sanitization and output escaping. Specifically, vulnerabilities arise from the [lvca_carousel] and [lvca_posts_carousel] shortcode attributes, which can be exploited by authenticated users with Contributor-level access or above. Attackers can inject malicious web scripts that execute when users access compromised pages, resulting in potential unauthorized actions and data exposure.
Affected Version(s)
WPBakery Page Builder Addons by Livemesh 0 <= 3.9.4