CVE-2026-1620Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name parameter in the `lae_get_template_part()` function, which uses an inadequate `str_replace()` approach that can be bypassed using recursive directory traversal patterns. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the attacker to include and execute local files via the widget's template parameter granted they can trick an administrator into performing an action or install Elementor.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-16); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-16: 3Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-24: 104-1604-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-163
Disclosure3
2026-04-241
Patch1
Full discourse4 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-1620 | CVSS 8.8 Livemesh Addons for Elementor (WordPress) vulnerable to Local File Inclusion in versions ≤9.0. Authenticated attackers (Contributor+) can execute arbitrary files. Patch immediately. #CVE #Vulnerability #PatchNow #WordPress https://t.co/5tDVMrvRT5

    Post summary

    The tweet alerts users to CVE-2026-1620, a high-severity LFI vulnerability in Livemesh Addons for Elementor, and urges immediate patching.

    0000060
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1620 Local File Inclusion in Livemesh Addons for Elementor Plugin Versions Up to 9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1620

    Post summary

    The post discloses an LFI flaw in Livemesh Addons for Elementor versions up to 9.0, but provides no proof of exploitation, active use, or patch information.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1620 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sani… https://www.cve.org/CVERecord?id=CVE-2026-1620

    Post summary

    The post announces the CVE-2026-1620 vulnerability, describing a Local File Inclusion flaw in Livemesh Addons for Elementor up to version 9.0, but does not mention PoC, exploitation, or mitigation measures.

    0000047
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-1620 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-1620 #WordPress #CyberSecurity #InfoSec

    Post summary

    A high‑severity (CVSS 8.8) Local File Inclusion flaw (CVE‑2026‑1620) in Livemesh Addons for Elementor has been announced, with a link to a detailed analysis.

    000001
    145 followersView on X

Explore more