Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-06-17

CVE-2026-1620 - Livemesh Addons For Elementor Plugin

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name parameter in the `lae_get_template_part()` function, which uses an inadequate `str_replace()` approach that can be bypassed using recursive directory traversal patterns. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the attacker to include and execute local files via the widget's template parameter granted they can…

PLUGIN Livemesh Addons For Elementor

CVE-2026-1620

HIGH CVSS 8.8 2026-04-16
Threat Entry Updated 2026-06-17

CVE-2026-1572 - Livemesh Addons For Elementor Plugin

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0. This is due to missing authorization checks on the AJAX handler `lae_admin_ajax()` and insufficient output escaping on multiple checkbox settings fields. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in the plugin settings page that will execute whenever an administrator accesses the plugin settings page granted they can obtain a valid…

PLUGIN Livemesh Addons For Elementor

CVE-2026-1572

MEDIUM CVSS 6.4 2026-04-16
Threat Entry Updated 2026-07-24

CVE-2026-39636 - Livemesh Addons for Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through

PLUGIN Livemesh Addons for Elementor

CVE-2026-39636

MEDIUM CVSS 6.5 2026-04-08
Scroll to top