Impact
The vulnerability is a stored cross-site scripting flaw that allows authenticated users with Contributor permissions or higher to inject malicious JavaScript into widget parameters of pages created with the plugin. The injected scripts execute automatically when any user loads the page, enabling an attacker to hijack user sessions, deface content, or modify site behavior. The weakness is a classic input validation and output escaping failure, classified as CWE‑79.
Affected Systems
The affected product is the Addon Elements for Elementor WordPress plugin, distributed by wpvibes (formerly Elementor Addon Elements). All releases up to and including version 1.14.3 are vulnerable; later versions have fixed the issue.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and works via normal page editing workflows, making it feasible for any user with Contributor-level access to craft malicious widgets that later execute for all visitors.
OpenCVE Enrichment