Impact
Liton Arefin Image Hover Effects for Elementor stores user supplied data in the database without proper encoding, allowing a stored cross‑site scripting attack. An attacker can embed malicious scripts that execute when a page using that image hover effect is viewed, potentially leading to session hijacking, cookie theft or page defacement. The vulnerability is identified as CWE‑79 and has a CVSS score of 6.5, indicating moderate severity.
Affected Systems
The affected product is the WordPress plugin Image Hover Effects for Elementor published by Liton Arefin. All releases from the earliest version up to and including 1.0.2.4 contain the flaw; newer releases are not listed as vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates exploitation is considered unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is during the storage of data in the plugin’s settings or content fields, which can be accessed by any authenticated user with permission to edit the plugin. Once stored, the malicious payload runs for every visitor to pages that load the compromised image hover results. The CVSS score of 6.5 reflects moderate risk, but the low exploitation probability moderates the overall urgency.
OpenCVE Enrichment
EUVD