Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.8.
Published: 2025-01-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is a DOM‑based Cross‑Site Scripting vulnerability caused by the Black Widgets For Elementor plugin failing to properly neutralize user input during web page rendering. When an attacker injects malicious script into widget content or parameters, the script executes in the browser of any user who views the affected page. This can lead to session hijacking, credential theft, or the execution of arbitrary code within the victim’s session. The flaw is classified as a moderate severity issue (CVSS 6.5), which indicates a non‑critical yet potentially damaging attack if exploited.

Affected Systems

The vulnerability affects the Black Widgets For Elementor plugin developed by Modernaweb Studio. All releases from no‑specified baseline version up through 1.3.8 are vulnerable. Users running any of these versions on a WordPress installation should assume the risk applies.

Risk and Exploitability

The risk is moderate with a CVSS score of 6.5 and an EXploit Propensity Scoring System (EPSS) score of less than 1 %. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The likely attack vector is web‑based: an attacker who can embed malicious content into a widget or a page that the end‑user subsequently views enables the DOM‑based XSS. Successful exploitation requires user interaction but is otherwise straightforward for an attacker with web access rights to manipulate widget content.

Generated by OpenCVE AI on May 1, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Black Widgets For Elementor to the latest version (1.3.9 or later).
  • If an immediate upgrade is not possible, remove all instances of the vulnerable widget from active pages to block injection vectors.
  • Disable or uninstall the Black Widgets For Elementor plugin entirely until the vendor releases a fix.

Generated by OpenCVE AI on May 1, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3010 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.8.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Thu, 20 Mar 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Modernaweb
Modernaweb black Widgets For Elementor
CPEs cpe:2.3:a:modernaweb:black_widgets_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Modernaweb
Modernaweb black Widgets For Elementor

Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.
Title WordPress Black Widgets For Elementor plugin <= 1.3.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Modernaweb Black Widgets For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:07.474Z

Reserved: 2025-01-07T21:05:34.185Z

Link: CVE-2025-22806

cve-icon Vulnrichment

Updated: 2025-01-10T20:18:41.416Z

cve-icon NVD

Status : Modified

Published: 2025-01-09T16:16:30.090

Modified: 2026-04-23T15:23:39.183

Link: CVE-2025-22806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:00:14Z

Weaknesses