Impact
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to stored cross‑site scripting through the Type Out widget. The vulnerability arises from insufficient input sanitization and output escaping of user‑supplied attributes. An attacker who is authenticated with contributor‑level access or higher can insert arbitrary JavaScript into the widget’s attributes. When a visitor loads a page that contains the compromised widget, the injected script executes in the visitor’s browser.
Affected Systems
Ultra Addons Lite for Elementor plugin for WordPress versions up to and including 1.3.2. WordPress sites operating any of these plugin releases are affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The exploitation requires an authenticated contributor or higher and results in client‑side script execution that can potentially compromise visitor data or interfere with site behavior.
OpenCVE Enrichment