Impact
The HT Event plugin for Elementor contains an improper neutralization of input flaw that enables reflected cross‑site scripting. When a maliciously crafted URL containing user-controlled data is accessed, the plugin directly inserts the input into a page without proper sanitization, allowing the attacker to inject arbitrary JavaScript into the victim’s browser. Such injected code can steal cookies, hijack session tokens or perform actions on behalf of the user, potentially compromising accounts or defacing content.
Affected Systems
Vendor DevItems offers the HT Event plugin for Elementor. All releases from n/a through version 1.4.6 are affected; any site running a version of the plugin at or below 1.4.6 is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, and the EPSS score of <1% reflects a very low expectation of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to persuade a victim to visit a specifically crafted URL; no server‑side compromise is possible, and the effect is limited to client‑side code execution.
OpenCVE Enrichment
EUVD