PT-2026-33275 · WordPress · Livemesh Addons For Elementor

Craig Smith

·

Published

2026-04-16

·

Updated

2026-04-24

·

CVE-2026-1620

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Livemesh Addons for Elementor versions prior to 9.1
Description The plugin is subject to Local File Inclusion due to insufficient sanitization of the template name parameter within the lae get template part() function. The implementation uses an inadequate str replace() method that can be bypassed using recursive directory traversal patterns. This allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary local files on the server by manipulating the widget's template parameter.
Recommendations Update the plugin to a version later than 9.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1620

Affected Products

Livemesh Addons For Elementor