CVE-2026-3896

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subscriber-level access and above to modify plugin settings and inject malicious scripts that execute when administrators access the plugin settings page or when any user visits the frontend.
Configurations

No configuration.

History

27 May 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 08:16

Updated : 2026-06-17 10:44


NVD link : CVE-2026-3896

Mitre link : CVE-2026-3896

CVE.ORG link : CVE-2026-3896


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization