CVE-2025-8780

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Livemesh SiteOrigin widgets features huge collection of premium, easy to use yet highly functional widgets that can be used in a page builder like <a href="https://wordpress.org/plugins/siteorigin-panels/" rel="nofollow ugc">SiteOrigin</a> or in any widgetized area of your site. This is really a premium plugin that you can get for free.</p> <p>This plugin comes with widgets for just about everything you need to build a professional website without switching to a premium theme &#8211; hero headers, services, team profiles, statistics, testimonials, clients list, portfolio/posts grid, carousels, varieties of tabs, accordions, buttons, icon lists, pricing plan and much more in the <a href="https://livemeshwp.com/siteorigin-widgets/" title="Livemesh SiteOrigin Widgets Premium Version" rel="nofollow ugc">PRO version</a>. All the widgets that help turn your free theme into a premium one with just a few clicks. Every premium page builder element you need is available for easy drag and drop into your page by just activating this plugin.</p> <p><a href="https://wordpress.org/plugins/so-widgets-bundle/" rel="ugc">SiteOrigin Widgets Bundle</a> plugin must be activated to use this plugin. After you activate the required plugins, enable our widgets by going to Plugins &gt; SiteOrigin Widgets in your WordPress admin.</p> <p>Although not required, <a href="https://wordpress.org/plugins/siteorigin-panels/" rel="nofollow ugc">Page Builder by SiteOrigin</a> is recommended.</p> <p>See the all of widgets in action here &#8211;</p> <p><a href="https://livemeshwp.com/siteorigin-widgets/widgets-demo#demo-section" title="Livemesh SiteOrigin Widgets Demo Site" rel="nofollow ugc"><strong>LIVE DEMO</strong></a> | <a href="https://livemeshwp.com/siteorigin-widgets/pricing/" title="Livemesh SiteOrigin Widgets Premium Version" rel="nofollow ugc"><strong>PRO Version</strong></a>.</p> <p>The plugin comes with the following widgets. <strong>Almost all of the widgets come with a dark version.</strong> &#8211;</p> <ul> <li><a href="https://livemeshwp.com/siteorigin-widgets/services/" title="Services Extension" rel="nofollow ugc">Services</a> that capture what you can offer for your clients/customers.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/portfolio-grid/" title="Portfolio Grid Widget" rel="nofollow ugc">Portfolio Grid widget</a> that displays portfolio/blog entries in a nice responsive grid. Masonry and packed options are supported.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/posts-grid/" title="Posts Grid Extension" rel="nofollow ugc">Blog Posts Grid</a> that displays portfolio/blog entries in a nice responsive grid. Masonry and packed options are supported.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/tabs/" title="Tabs Widget" rel="nofollow ugc">Responsive Tabs</a> that function seamlessly across all devices and resolutions. The plugin features never before choice of over dozen styles of tabs to choosen from a simple widgets editor dropdown.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/accordion/" title="Accordion Module" rel="nofollow ugc">Accordion/Toggle</a> that capture collapsible content panels when space is limited.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/hero-headers/" title="Hero Header Widget" rel="nofollow ugc">Hero Header Widget</a> that lets you display any type of header content with option to set Parallax, YouTube or HTML5 video background.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/team-member-profiles/" title="Team Profiles Widget" rel="nofollow ugc">Team Profiles</a> extension to display all the team members.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/odometer-counters/" title="Odometer/Counters Extension" rel="nofollow ugc">Odometers/Counters</a> to show impressive numbers pertaining to your work or company.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/bar-charts/" title="Bar Charts" rel="nofollow ugc">Bar charts widget</a> to capture skills or any type of percentage stats with just a few clicks in SiteOrigin Page Builder or any widgetized area of your site.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/piecharts/" title="Piecharts Extension" rel="nofollow ugc">Animated Pie charts</a> for visual depiction of percentage stats.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/testimonials/" title="Testimonials Widget" rel="nofollow ugc">Testimonials</a> to tell everyone the good things you often hear from your clients/customers.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/testimonial-slider/" title="Testimonial Slider Widget" rel="nofollow ugc">Testimonials slider</a> is a responsive touch enabled slider that cycles through testimonials.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/posts-carousel/" title="Posts Carousel Extension" rel="nofollow ugc">Post Carousel extension</a> that displays your posts as a highly responsive carousel.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/generic-carousel/" title="Generic Carousel Widget" rel="nofollow ugc">Generic Carousel</a> element that displays lets you present a list of HTML content in a carousel.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/buttons/" title="Buttons" rel="nofollow ugc">Flat style buttons</a> with rich set of customization options.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/icon-lists/" title="Icon List element" rel="nofollow ugc">Icon list widget</a> that lets you use either images or icon fonts to create custom social icons list, capture payment options etc.</li> <li>Heading styles to capture effective headings for your page sections.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/clients-widget/" title="Clients List Element" rel="nofollow ugc">Clients List</a> extension to showcase the clients that you have handled.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/pricing-table/" title="Pricing Table Extension" rel="nofollow ugc">Pricing Plans</a> to help get more sales.</li> </ul> <p>The <strong><a href="https://livemeshwp.com/siteorigin-widgets/" title="Livemesh SiteOrigin Widgets Pro" rel="nofollow ugc">PRO version</a></strong> of the plugin comes with additional SiteOrigin widgets and advanced features added to elements above &#8211;</p> <ul> <li><a href="https://livemeshwp.com/siteorigin-widgets/posts-slider/" title="Posts Slider Addon" rel="nofollow ugc">Posts Slider</a> that helps showcase your posts as a highly responsive, touch enabled slider.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/posts-gridbox-slider/" title="Posts Gridbox Slider Addon" rel="nofollow ugc">Posts Gridbox Slider</a> that displays your posts as a slider of tiled post grids.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/posts-multislider/" title="Posts Multislider Addon" rel="nofollow ugc">Posts Multislider</a> that helps showcase your posts as a highly responsive, touch friendly carousel.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/sliders/" title="Image Slider Extension" rel="nofollow ugc">Image Slider</a> to create a responsive slider of images with support for captions, multiple slider types like Nivo, Flex, Slick and lightweight sliders, thumbnail navigation etc.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/image-gallery/" title="Image Gallery Widget" rel="nofollow ugc">Image Gallery</a> widget that lets you create a grid of images with options for masonry or fit rows, pagination, lazy load, lightbox support etc. </li> <li><a href="https://livemeshwp.com/siteorigin-widgets/video-gallery/" title="Video Gallery Widget" rel="nofollow ugc">Video Gallery</a> to build a beautiful grid of videos to help showcase a collection of YouTube/Vimeo videos on your site.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/gallery-carousel/" title="Image Carousel" rel="nofollow ugc">Image Carousel</a> for a responsive carousel of images.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/gallery-carousel/" title="Video Carousel" rel="nofollow ugc">Video Carousel</a> for creation of a responsive carousel of YouTube/Vimeo videos.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/faq-widget/" title="FAQ Element" rel="nofollow ugc">FAQ element</a> to display a set of Frequently Asked Questions in a page.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/features-widget/" title="Features Widget" rel="nofollow ugc">Features Widget</a> for showcasing product features or services provided by an agency/business.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/services-advanced/" title="Advanced Services" rel="nofollow ugc">Advanced Services</a> with additional styles and animations for services widget.</li> <li>Countdown widget to display a countdown timer on your site pages such as those that feature events or under construction/coming soon pages.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/portfolio-grid-pro/" title="Posts Grid" rel="nofollow ugc">Lazy Load</a> &#8211; The portfolio/post grid and image gallery widgets incorporate option to lazy load posts/images with the click of a Load More button.</li> <li><a href="https://livemeshwp.com/siteorigin-widgets/portfolio-grid-pro/" title="Posts Grid" rel="nofollow ugc">Pagination</a> &#8211; Create a grid of posts or custom post types with AJAX based pagination support. </li> <li>Lightbox Support &#8211; The premium version of Livemesh SiteOrigin Widgets plugin comes with support for Lightbox for grid and carousel widgets.</li> <li>Customizations &#8211; Ability to choose custom font size, color or hover color for certain widgets. More coming.</li> <li>Custom Fonts &#8211; Ability to choose custom fonts from Google Fonts library for headings in heading widget and the hero header widget.</li> <li>Custom Animations &#8211; Choose from over <strong>40+ animations</strong> for most widgets (excludes sliders, carousels and grid). The animations display on user scrolling to the element or when the element becomes visible in the browser window.</li> <li>Sample Data &#8211; Sample data that you can import into your site to get started quickly on the widgets and some sample layouts.</li> <li>Premium Support &#8211; The customers will have access to a support portal with queries attended to within 24 hours.</li> </ul> <p><strong>Important: You must activate widgets you need to use from Plugins &gt; SiteOrigin Widgets so that they can be available to use.</strong>.</p> <p>You can view the change log for the Premium version of the plugin at <a href="https://livemeshwp.com/siteorigin-widgets/change-log/" title="Livemesh SiteOrigin Widgets Premium Change Log" rel="nofollow ugc">https://livemeshwp.com/siteorigin-widgets/change-log/</a>.</p> <h3>Support</h3> <p>The premium version of the plugin entitles you to quick support with replies posted within 24 hours (on week days).</p> <p>Please submit your support query through our <a href="https://livemeshwp.com/siteorigin-widgets/contact-us/" title="Livemesh Contact form" rel="nofollow ugc">website contact form</a>. This will create a support ticket in our support portal.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.2M