Impact
Improper neutralization of user input in the Elementor AI Addons plugin permits DOM‑based XSS. An attacker can embed malicious scripts that execute in the victim’s browser, allowing arbitrary client‑side code to run.
Affected Systems
Affected systems include WordPress websites that use the Harnani Elementor AI Addons plugin version 2.2.1 or earlier. Versions newer than 2.2.1 are not vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1 % shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is DOM‑based XSS, exploitation requires a victim to interact with malicious content processed by the plugin; the attacker can only run code in the victim’s browser and does not gain remote code execution.
OpenCVE Enrichment
EUVD