← WordPress Vulnerabilities
WordPress security by component

Livemesh Addons by Elementor

Livemesh Addons by Elementor is a WordPress component with 23 published CVE records in this archive. The latest tracked vulnerability was published Apr 16, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: addons-for-elementor

CVE-2026-1620: Livemesh Addons by Elementor: Filesystem traversal

Livemesh Addons by Elementor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 9.0.

PublishedApr 16, 2026
Known safe version> 9.0
Safe version
Apr 16, 2026 CVE-2026-1620
Livemesh Addons by Elementor: Filesystem traversal
Livemesh Addons by Elementor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 9.0.
> 9.0
CVE8.8
NVDPending
Apr 16, 2026 CVE-2026-1572
Livemesh Addons by Elementor: Cross-site scripting
Livemesh Addons by Elementor is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.0.
> 9.0
CVE6.4
NVDPending
Apr 08, 2026 CVE-2026-39636
Livemesh Addons for Elementor: Cross-site scripting
Livemesh Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.0.
> 9.0
CVE6.5
NVDPending
Sep 25, 2024 CVE-2024-8858
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 25, 2024 CVE-2024-47303
Livemesh Addons for Elementor: Cross-site scripting
Livemesh Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 06, 2024 CVE-2024-37547
Livemesh Addons for Elementor: Filesystem traversal
Livemesh Addons for Elementor is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVD6.5
Jul 04, 2024 CVE-2024-3639
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 04, 2024 CVE-2024-3638
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 04, 2024 CVE-2024-2926
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 04, 2024 CVE-2024-2385
Elementor Addons by Livemesh: Filesystem traversal
Elementor Addons by Livemesh is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Apr 10, 2024 CVE-2024-2655
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-2539
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1466
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1465
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1464
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1461
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1458
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 15, 2024 CVE-2024-25598
Livemesh Addons for Elementor: Cross-site scripting
Livemesh Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 14, 2024 CVE-2024-27986
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Feb 29, 2024 CVE-2024-1235
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0448
Elementor Addons by Livemesh: Cross-site scripting
Elementor Addons by Livemesh is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 12, 2022 CVE-2022-3862
Livemesh Addons for Elementor: Cross-site scripting
Livemesh Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 05, 2021 CVE-2021-24260
“Livemesh Addons for Elementor”: Cross-site scripting
“Livemesh Addons for Elementor” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4