PT-2026-33275 · WordPress · Livemesh Addons For Elementor
Craig Smith
·
Published
2026-04-16
·
Updated
2026-04-24
·
CVE-2026-1620
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Livemesh Addons for Elementor versions prior to 9.1
Description
The plugin is subject to Local File Inclusion due to insufficient sanitization of the template name parameter within the
lae get template part() function. The implementation uses an inadequate str replace() method that can be bypassed using recursive directory traversal patterns. This allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary local files on the server by manipulating the widget's template parameter.Recommendations
Update the plugin to a version later than 9.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livemesh Addons For Elementor