Stored Cross-Site Scripting Vulnerability in WPBakery Page Builder Addons by Livemesh
CVE-2026-2030

6.4MEDIUM

What is CVE-2026-2030?

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is subjected to a Stored Cross-Site Scripting vulnerability due to improper input sanitization and output escaping. Specifically, vulnerabilities arise from the [lvca_carousel] and [lvca_posts_carousel] shortcode attributes, which can be exploited by authenticated users with Contributor-level access or above. Attackers can inject malicious web scripts that execute when users access compromised pages, resulting in potential unauthorized actions and data exposure.

Affected Version(s)

WPBakery Page Builder Addons by Livemesh 0 <= 3.9.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.