Stored Cross-Site Scripting Vulnerability in WPBakery Page Builder Addons by Livemesh
CVE-2026-3895

6.4MEDIUM

What is CVE-2026-3895?

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is susceptible to Stored Cross-Site Scripting through the lvca_admin_ajax AJAX action. This vulnerability, present in all versions up to and including 3.9.4, arises from the absence of proper authorization checks and inadequate input sanitization. While a nonce is verified, the handler does not assess user capabilities, allowing authenticated users with Subscriber-level access and higher to alter plugin settings and inject malicious JavaScript. These scripts can execute when administrators access the plugin settings page or whenever any user visits the site frontend, posing significant security risks.

Affected Version(s)

WPBakery Page Builder Addons by Livemesh 0 <= 3.9.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.