Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Livemesh Addons by Elementor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Livemesh Addons by Elementor, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities and weaknesses associated with Livemesh Addons by Elementor, categorized under common weakness enumeration tags for software security. It aggregates reports on security flaws ranging from injection attacks to cross-site scripting and insufficient access control mechanisms affecting this popular WordPress plugin ecosystem. The database covers advisory disclosures and tracked incidents spanning from the product's initial release to the most recent updates, ensuring a comprehensive historical view of its security posture over time. Visitors can utilize this resource to track a vendor's advisories and understand the specific nature of each weakness class identified within the codebase. By examining the chronological data, users can look up a product's vulnerability history to assess risk trends and evaluate the effectiveness of past remediation efforts. This aggregated view helps developers and site administrators identify recurring patterns in security issues, such as specific input validation failures or configuration missteps, which may persist across different versions. Understanding these historical trends is crucial for prioritizing patches and implementing robust security controls. The information serves as a factual record of known issues, facilitating informed decision-making regarding plugin updates and server-side hardening strategies. It does not speculate on unreported bugs or provide speculative analysis beyond the documented facts. The goal is to provide clarity on the security landscape surrounding this specific tool, enabling stakeholders to make data-driven decisions about their deployment environments.

Vendor: livemesh

CVE IDTitleCVSSSeverityPublished
CVE-2026-1572 Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings CWE-79 6.4 Medium2026-04-16
CVE-2026-1620 Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter CWE-98 8.8 High2026-04-16
CVE-2024-8858 Elementor Addons by Livemesh <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via piechart_settings Parameter CWE-79 6.4 Medium2024-09-25
CVE-2024-3639 Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid CWE-79 6.4 Medium2024-07-04
CVE-2024-2926 Elementor Addons by Livemesh <= 8.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Various Widgets CWE-79 6.4 Medium2024-07-04
CVE-2024-2385 Elementor Addons by Livemesh <= 8.4 - Authenticated (Contributor+) Limited Local File Inclusion via Widgets CWE-22 8.8 High2024-07-04
CVE-2024-3638 Elementor Addons by Livemesh <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Marquee Text Widget, Testimonials Widget, and Testimonial Slider Widgets CWE-79 6.4 Medium2024-07-04
CVE-2024-2655 Elementor Addons by Livemesh <= 8.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name CWE-79 6.4 Medium2024-04-10
CVE-2024-2539 Elementor Addons by Livemesh <= 8.3.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via widget _id attribute CWE-79 6.4 Medium2024-04-10
CVE-2024-1458 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1461 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1465 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Carousel Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1464 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1466 Elementor Addons by Livemesh <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget CWE-79 6.4 Medium2024-04-09
CVE-2024-1235 Elementor Addons by Livemesh <= 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0448 Elementor Addons by Livemesh <= 8.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-05

All 16 known CVE vulnerabilities affecting Livemesh Addons by Elementor with full Chinese analysis, references, and POCs where available.