VYPR
Medium severity6.5NVD Advisory· Published Aug 18, 2024· Updated Apr 15, 2026

CVE-2024-43320

CVE-2024-43320

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Livemesh Addons for WPBakery Page Builder plugin (≤3.9) allows attackers to inject malicious scripts via improper input neutralization.

The vulnerability is a stored cross-site scripting (XSS) issue in the Livemesh Addons for WPBakery Page Builder WordPress plugin, versions up to 3.9. It stems from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary HTML and JavaScript into pages [1].

Exploitation requires a privileged user, such as an administrator, to perform an action like clicking a malicious link or submitting a crafted form. This user interaction is necessary for the attack to succeed, but once triggered, the injected script is stored and executed when other users visit the affected page [1].

The impact includes the ability to inject malicious scripts that can redirect visitors, display advertisements, or deliver other HTML payloads. This could be used in mass-exploit campaigns targeting thousands of WordPress sites, regardless of their size or popularity [1].

As a mitigation, the vendor has released version 3.9.1, which resolves the vulnerability. Users are advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. While the CVSS score is 6.5 (Medium), the advisory notes that the severity is considered low and exploitation is unlikely, but proactive updating is recommended [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.