Livemeshelementor develops add-ons for the Elementor page-builder platform, a widely used WordPress ecosystem component, with its vulnerability footprint centered on the Addons for Elementor product. The recurring weakness classes affecting this vendor's offering—cross-site scripting, path traversal, and related input-handling flaws—reflect the web-application context and user-controlled content typical of WordPress plugins and builders. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Livemeshelementor over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2385HIGH The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of the plugin's widgets through th | Jul 4, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-2926MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 8.3.7 due to insuf | Jul 4, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-1466MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style’ attribute of the Posts Multislider widget in all versions | Apr 9, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-1464MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Posts Slider widget in all versions up to, and i | Apr 9, 2024 | 5.4 | 19 | NO | NO |
CVE-2022-3862MEDIUM The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform S | Dec 12, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-8858MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 d | Sep 25, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-47303MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Cross-Site | Sep 25, 2024 | 5.4 | 18 | NO | NO |
CVE-2021-24260MEDIUM The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contr | May 5, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-3639MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Posts Grid widget in all versions up to, and including, 8.3.7 d | Jul 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-2655MEDIUM The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post widgets in all versions up to, and including, 8.3.5 due to | Apr 10, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Livemeshelementor.
Media articles that mention a CVE ID that affects a product developed by Livemeshelementor — matched by CVE ID, not by vendor name.