Impact
A stored cross-site scripting issue exists in Livemesh Addons for WPBakery Page Builder versions up to 3.9.4. The vulnerability allows contributors to embed unsanitized JavaScript into page content. When visitors load the affected pages, the injected script executes in their browsers. This flaw is identified as CWE-79.
Affected Systems
WordPress sites that have installed Livemesh Addons for WPBakery Page Builder version 3.9.4 or older are affected. The plugin is distributed as a bundle for WPBakery Page Builder, and the vulnerability exists in that bundle. All users who can add or edit content via the WordPress editor (e.g., contributors) can exercise the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity a low probability of widespread exploitation, the fact that the flaw is stored XSS means any injected script will run for all visitors who view the affected pages. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of active exploitation. An attacker would leverage the contributor role within the WordPress site's backend to inject malicious JavaScript into page content; the attack requires access to the editor interface and does not need to compromise the server. Once injected, the script executes in the browsers of site visitors, creating a risk of cookie theft or phishing. Prompt patching is recommended.
OpenCVE Enrichment