Impact
This vulnerability is an improper neutralization of user input that allows an attacker to inject malicious scripts into web pages rendered by the Livemesh Addons for WPBakery Page Builder plugin. The injected scripts run in the context of site visitors, enabling session hijacking, data theft, defacement, or further payload delivery. The impact is limited to the scope of the website but can have broad consequences for all users who view affected pages.
Affected Systems
The plugin Livemesh Addons for WPBakery Page Builder, versions up through 3.9.4, is vulnerable. All users of this plugin on WordPress installations are affected unless upgraded beyond the specified version.
Risk and Exploitability
The CVSS score of 5.9 rates this as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the current environment. Although it has not been listed in the CISA KEV catalog, the vulnerability can be abused via the plugin’s content editing interface, where arbitrary HTML can be stored and later served to any site visitor. An attacker who can create or modify content within the plugin can persistently store XSS payloads that activate when other users load the affected pages.
OpenCVE Enrichment