Impact
The Livemesh Addons for Beaver Builder plugin allows a stored cross‑site scripting attack when an authenticated user with at least Subscriber privileges calls the labb_admin_ajax endpoint. The handler verifies only a nonce and performs no capability check, then stores the supplied value directly into plugin settings. Because the value is executed when an administrator opens the plugin settings or when any user visits the front‑end, an attacker can embed malicious JavaScript that runs in the context of privileged users, potentially stealing session cookies, impersonating administrators, or defacing the site.
Affected Systems
All installations of Livemesh Addons for Beaver Builder up to and including version 3.9.2 on WordPress are affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is rated medium. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated WordPress account, but the privilege level needed is only Subscriber or higher, which is common on many sites. Once the attack vector is established the malicious script will persist in stored plugin settings and will be served to any browsing administrator or front‑end user, making it a significant risk when privileged accounts are compromised.
OpenCVE Enrichment