Impact
The vulnerability is a stored Cross‑Site Scripting flaw caused by improper neutralization of user input during page generation. When malicious input is saved through the widget, it is rendered without sanitization, enabling an attacker to inject and execute arbitrary JavaScript in the browsers of page visitors. This can lead to session hijacking, defacement, data theft, or other client‑side attacks.
Affected Systems
The flaw affects the WordPress plugin News Ticker Widget for Elementor created by Aezaz Shaikh. All versions equal to or older than 1.3.2 are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability with potential damage to confidentiality, integrity, and availability of user data. The EPSS score of less than 1% suggests that, historically, exploitation occurrences are very rare, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an authenticated user (typically an administrator) adding malicious content to the widget configuration, which is then stored in the database and rendered on the site, delivering the injected payload to all visitors who load the affected page.
OpenCVE Enrichment
EUVD