Livemesh Addons for Elementor Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in the Livemesh Addons for Elementor plugin for WordPress, affecting all versions through 9.0. The issue arises from inadequate sanitization of the template name parameter in the 'lae_get_template_part()' function. This vulnerability allows authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. Exploitation requires tricking an administrator into taking an action or installing Elementor.

Impact

Exploitation of this vulnerability could lead to unauthorized inclusion and execution of local files on the server, potentially allowing for further exploitation or access escalation.

Reproduction

To reproduce this vulnerability, an authenticated user with Contributor-level access or higher can manipulate the widget's template parameter to include a file from the server. This is done by using recursive directory traversal patterns to bypass the plugin's basic sanitization, exploiting the 'lae_get_template_part()' function.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Apr 16, 2026, 8:13 AM
Updated: Apr 16, 2026, 8:13 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
7.5
exploitability
6.4
remediation
0.0
relevance
6.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.