漏洞关键信息 漏洞标题 Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE 编号 CVE-2026-2029 CVSS 分数 6.4 (Medium) 公开发布日期 February 25, 2026 最后更新日期 February 26, 2026 研究者 Muhammad Yudha - DJ 漏洞类型 Improper Neutralization of Input During Web Page Generation 软件类型 Plugin 软件 Slug addons-for-beaver-builder 是否已修复 No 补救措施 No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. 影响版本 <= 3.9.2 漏洞描述 The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[labb_pricing_item]' shortcode's and attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, the plugin uses after , which decodes HTML entities back into executable code after sanitization has occurred. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 参考链接 plugins.trac.wordpress.org plugins.trac.wordpress.org