WPBakery Page Builder Addons by Livemesh

WPBakery Page Builder Addons by Livemesh has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; 6 are fixed and 4 remain unpatched as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (80%). Other recurring categories include Missing Authorization.

6 of the records (60%) have a vendor fix, while 4 remain unpatched. The oldest unresolved one dates back to 2026.

7 independent researchers contributed these findings, most of them (2) reported by Abu Hurayra (HurayraIIT).

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage60%
Open

4

Fixed

6

Get automatic notifications for all WPBakery Page Builder Addons by Livemesh vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2026-57754

WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

10 records
2026-07-02 00:00CVE-2026-57754
6.4
Medium
timomangcutNo
2026-05-26 17:34CVE-2026-2030
6.4
Medium
Muhammad Yudha - DJNo
2026-05-26 17:33CVE-2026-3895
6.4
Medium
Muhammad Yudha - DJNo
2026-01-15 00:00CVE-2026-24594
4.4
Medium
ZadWonNo
2024-08-16 00:00CVE-2024-43320
6.4
Medium
LVT-tholv2kYes
2024-03-25 00:00CVE-2024-30183
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2024-03-13 00:00CVE-2024-2079
6.4
Medium
Krzysztof ZającYes
2023-12-07 00:00CVE-2023-50370
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2023-07-18 00:00CVE-2023-33999
6.1
Medium
Rafie MuhammadYes
2022-03-04 00:00CVE-2022-4974
6.3
Medium
AnonymousYes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C