Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Livemesh Addons by Elementor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Livemesh Addons by Elementor, with AI-generated Chinese analysis, references, and POCs.

Livemesh Addons by Elementor is a WordPress plugin that contains multiple software vulnerabilities categorized under insecure direct object references and cross-site scripting weaknesses. This page aggregates comprehensive vulnerability data for the Livemesh Addons by Elementor product, covering security issues reported between 2021 and 2024. It serves as a centralized repository for analyzing the security posture of this specific plugin ecosystem, ensuring that developers and security professionals have access to a consolidated view of known flaws. Users can track vendor advisories to stay informed about official patches and mitigation strategies as they are released by the maintainers. The resource allows for a deep dive into specific weakness classes, helping administrators understand the technical nature of the exploits and their potential impact on web applications. Additionally, individuals can look up a product's vulnerability history to assess the frequency and severity of past incidents, facilitating better risk management decisions. By examining the chronological progression of these security issues, stakeholders can identify patterns in development practices and prioritize updates accordingly. This aggregation aims to provide clarity and actionable intelligence for those relying on the Livemesh Addons by Elementor suite within their WordPress environments. It is designed to support informed decision-making without unnecessary noise or unverified claims. The content focuses strictly on factual security data to aid in effective threat mitigation and compliance auditing processes.

Vendor: livemesh

CVE IDTitleCVSSSeverityPublished
CVE-2026-1572 Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings CWE-79 6.4 Medium2026-04-16
CVE-2026-1620 Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter CWE-98 8.8 High2026-04-16
CVE-2024-8858 Elementor Addons by Livemesh <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via piechart_settings Parameter CWE-79 6.4 Medium2024-09-25
CVE-2024-3639 Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid CWE-79 6.4 Medium2024-07-04
CVE-2024-2926 Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Various Widgets CWE-79 6.4 Medium2024-07-04
CVE-2024-2385 Elementor Addons by Livemesh <= 8.4 - Authenticated (Contributor+) Limited Local File Inclusion via Widgets CWE-22 8.8 High2024-07-04
CVE-2024-3638 Elementor Addons by Livemesh <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Marquee Text Widget, Testimonials Widget, and Testimonial Slider Widgets CWE-79 6.4 Medium2024-07-04
CVE-2024-2655 Elementor Addons by Livemesh <= 8.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name CWE-79 6.4 Medium2024-04-10
CVE-2024-2539 Elementor Addons by Livemesh <= 8.3.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via widget _id attribute CWE-79 6.4 Medium2024-04-10
CVE-2024-1458 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1461 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1465 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Carousel Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1464 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1466 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1235 Elementor Addons by Livemesh <= 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0448 Elementor Addons by Livemesh <= 8.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-05

All 16 known CVE vulnerabilities affecting Livemesh Addons by Elementor with full Chinese analysis, references, and POCs where available.