Impact
Improper neutralization of input during page generation in WPDeveloper Essential Addons for Elementor allows attackers to inject malicious scripts that execute in the victim’s browser. Based on the description, it appears that the vulnerability can be triggered by crafted requests to the plugin’s input fields, leading to the execution of arbitrary JavaScript, potentially compromising the confidentiality of user data, altering page content, or defacing the site. This is a classic reflected XSS flaw associated with CWE‑79.
Affected Systems
WordPress sites that have installed WPDeveloper Essential Addons for Elementor Lite version 6.0.14 or earlier. The affected product is the Lite version of the plugin, identified by the vendor WPDeveloper and the product name Essential Addons for Elementor.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity level, while the EPSS score of 4% suggests a non‑negligible chance of exploitation in the near future. The vulnerability is not listed in the CISA KEV catalog, but based on the description, the likely attack vector involves an attacker crafting a malicious link that the victim is encouraged to click, thereby triggering the reflected XSS. Successful exploitation would allow the attacker to run code with the victim user’s privileges, potentially revealing session data or delivering malicious payloads.
OpenCVE Enrichment
EUVD