Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to store malicious scripts in content managed by the Livemesh Addons for Beaver Builder plugin. When affected sites display that content, the scripts execute in the browsers of visitors, enabling cookie theft, defacement, or other client‑side attacks. The CVSS score of 6.5 classifies it as a moderate severity problem, affecting the confidentiality and integrity of site users.
Affected Systems
WordPress sites running Livemesh Addons for Beaver Builder plugin version 3.9.2 or earlier are vulnerable. This includes all installations that have not been upgraded beyond the stated version.
Risk and Exploitability
With a CVSS score of 6.5 and an EPSS score of less than 1%, the likelihood of active exploitation remains low. The attack vector is through the plugin’s content fields, which are stored without proper sanitization. The vulnerability does not require elevated privileges, but an attacker with access to the builder interface can insert malicious payloads that will later be delivered to site visitors.
OpenCVE Enrichment