PT-2026-43548 · Livemesh+1 · Livemesh Siteorigin Widgets

+1

·

CVE-2026-3896

·

Published

2026-05-26

·

Updated

2026-06-04

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Livemesh SiteOrigin Widgets versions prior to 3.9.3
Description Stored Cross-Site Scripting occurs via the lsow admin ajax AJAX action due to missing authorization checks and insufficient input sanitization. While the AJAX handler verifies a nonce, it fails to check user capabilities. This allows authenticated attackers with Subscriber-level access or higher to modify plugin settings and inject malicious scripts. These scripts execute when administrators access the plugin settings page or when any user visits the frontend.
Recommendations Update Livemesh SiteOrigin Widgets to version 3.9.3 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3896

Affected Products

Livemesh Siteorigin Widgets