Impact
Improper neutralization of input during web page generation in Thim Elementor Kit allows an attacker to inject arbitrary JavaScript into rendered pages. The DOM‑based XSS flaw can be triggered when the plugin processes user‑provided content, potentially leading to session hijacking, cookie theft, or defacement of the website.
Affected Systems
The vulnerable plugin is the Thim Elementor Kit bundled with WordPress by ThimPress. Versions up to and including 1.2.9 are affected and the issue applies to any site that has the plugin installed and active.
Risk and Exploitability
The CVSS score of 6.5 puts the vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA KEV. Exploitation requires that the plugin is enabled and that a user views content rendered by it, implying that a malicious actor would need to insert malicious content through the plugin’s input channels. Although the exploitation likelihood is low, the potential impact on confidentiality, integrity and availability warrants prompt action.
OpenCVE Enrichment
EUVD