Impact
The vulnerability permits the storage of arbitrary JavaScript that is later rendered inside WordPress pages that contain Yottie Lite blocks. Because the input is not sanitized, an attacker can embed malicious code that executes in visitors’ browsers, potentially allowing cookie theft, site defacement, or redirection to malicious sites.
Affected Systems
The affected product is Elfsight Yottie Lite, and any WordPress installation that has version 1.3.3 or older is vulnerable. This includes every site that has the plugin installed and has created or edited Yottie Lite content since the plugin’s first release.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of wild exploitation. The flaw can be triggered by input that is stored and served to all site visitors; the likely attack vector is that a user with permission to edit Yottie Lite blocks can inject malicious script. This inference is drawn from the description that the input is stored without sanitization. Because the stored payload is executed for any viewer, the impact covers all site users, though the risk is not catalogued in CISA KEV.
OpenCVE Enrichment
EUVD