VYPR
Medium severity5.9NVD Advisory· Published Jan 23, 2026· Updated Apr 28, 2026

CVE-2026-24594

CVE-2026-24594

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through <= 3.9.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Livemesh Addons for WPBakery Page Builder (≤3.9.4) allows attackers to inject malicious scripts via input neutralization failure.

The vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Livemesh Addons for WPBakery Page Builder plugin for WordPress, affecting versions from n/a through 3.9.4. The root cause is improper neutralization of user input during web page generation, where user-supplied input is not sanitized before being stored and later rendered in pages [1].

Exploitation requires a privileged user (e.g., an editor or admin) to perform an action such as clicking a malicious link or submitting a crafted form. Once triggered, the injected script is stored on the server and executed when other users (including visitors) access the affected page. No direct interaction with the attacker is not needed for the stored payload to fire [1].

An attacker can inject arbitrary JavaScript, HTML, or other payloads. This can lead to redirects, advertisement injection, data theft, or defacement. The CVSS v3 score of 5.9 (Medium) reflects the need for user interaction and privileges, but the stored nature increases the potential reach [1].

As of the publication date, the vendor advisories recommend updating the plugin to a patched version. If immediate update is not possible, users should restrict access to the plugin's settings and consider asking their hosting provider for assistance. The vulnerability is listed as used in mass-exploit campaigns, so prompt action is advised [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.