PT-2026-43548 · Livemesh+1 · Livemesh Siteorigin Widgets
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Livemesh SiteOrigin Widgets versions prior to 3.9.3
Description
Stored Cross-Site Scripting occurs via the
lsow admin ajax AJAX action due to missing authorization checks and insufficient input sanitization. While the AJAX handler verifies a nonce, it fails to check user capabilities. This allows authenticated attackers with Subscriber-level access or higher to modify plugin settings and inject malicious scripts. These scripts execute when administrators access the plugin settings page or when any user visits the frontend.Recommendations
Update Livemesh SiteOrigin Widgets to version 3.9.3 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livemesh Siteorigin Widgets