Impact
The vulnerability resides in the Improper Neutralization of Input During Web Page Generation in ElementsCSS Addons for Elementor, allowing an attacker to store malicious script code that is then executed in the browsers of users who view affected pages. This stored XSS can lead to cookie theft, session hijacking, defacement, or injection of further malware. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
The affected product is TheInnovs ElementsCSS Addons for Elementor for WordPress. Versions up through and including 1.0.8.9 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of real‑world exploitation is low at present, although a stored XSS is often activated by user interaction with a crafted page. Based on the description, the likely attack vector is via the web interface of the plugin, requiring an attacker to supply injected input that is later rendered to page visitors.
OpenCVE Enrichment
EUVD