Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter
Livemesh Addons by Elementor
Minimum safe version
8.5.1
Update to 8.5.1 or later to address 28 fixable vulnerabilities
Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings
CVE-2026-39636
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-8858
CVE-2024-47303
CVE-2024-37547
CVE-2024-2385
CVE-2024-3638
CVE-2024-2926
CVE-2024-3639
CVE-2024-2539
CVE-2024-2655
CVE-2024-27986
CVE-2024-1461
CVE-2024-1458
CVE-2024-1464
CVE-2024-1466
CVE-2024-1465
CVE-2024-25598
CVE-2024-1235
CVE-2024-0448
WordPress Livemesh Addons for Elementor Plugin < 7.9 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Livemesh Addons for Elementor Plugin <= 7.2.3 is vulnerable to Cross Site Scripting (XSS)
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Livemesh Addons for Elementor plugin <= 6.7.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Livemesh Addons for Elementor plugin <= 7.1.3 - Sensitive Information Disclosure vulnerability
WordPress Livemesh Addons for Elementor plugin <= 7.1.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24260