MEDIUM (6.1)
    Plugin

    Livemesh Addons for Elementor Local File Inclusion Vulnerability

    Published Date: 4/16/2026
    CVE ID: CVE-2026-1620

    Summary

    The Livemesh Addons for Elementor plugin up to version 9.0 is vulnerable to Local File Inclusion (LFI). This vulnerability allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server through insufficient sanitization of input parameters.

    Vulnerability Details

    The vulnerability occurs due to poor input sanitization in the `lae_get_template_part()` function, which processes the template name parameter. The function's use of a simple string replacement method fails to adequately filter out potentially malicious inputs. This oversight allows recursive directory traversal patterns to be used, leading to Local File Inclusion (LFI). Attackers with sufficient access can exploit this flaw to include sensitive files from the server, which may lead to leaks of sensitive information and potential arbitrary code execution. This vulnerability can be particularly dangerous if an attacker can manipulate an administrator into performing actions within the affected plugin's widget, thereby escalating the impact. The best practice in such coding scenarios is to employ stronger path sanitization methods to prevent exploitation attempts.

    Recommendations

    To mitigate this vulnerability, site administrators should immediately restrict access to the plugin's features from lower-privileged user roles, such as Contributors. Additionally, it's advisable to monitor server logs for any suspicious file access attempts and implement file permission policies that minimize access to sensitive directories.

    Available Fixes

    Last Updated: 4/19/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More