Impact
The Element Pack Addons for Elementor plugin contains a stored cross‑site scripting flaw that allows an authenticated user with Contributor or higher privileges to inject arbitrary scripts via widgets such as Dual Button, Creative Button, and Image Stack. The vulnerability arises from insufficient input sanitization and output escaping, causing malicious code to be stored in the database and executed when a user views the impacted page.
Affected Systems
All released versions of the bdthemes Element Pack Lite plugin for Elementor up to and including version 5.10.29 are affected. A WordPress site that has installed this plugin with any of the vulnerable widgets enabled is susceptible; the flaw does not extend to other Elementor add‑on packages that do not contain these widgets.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as moderate, while an EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers must be authenticated with Contributor‑level or higher privileges, so they are typically limited to users who have editing rights within the Elementor editor. Once authenticated, the attacker can embed malicious scripts that run in the browsers of all users who view the affected page, potentially allowing execution of further payloads.
OpenCVE Enrichment
EUVD