Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in the Easy Elementor Addons plugin. Unsanitized user input is incorporated directly into web page generation, allowing an attacker to inject arbitrary JavaScript that will execute in any user’s browser. This can enable defacement, data theft, or session hijacking by malicious scripts that run with the victim’s privileges.
Affected Systems
The issue affects the WordPress Easy Elementor Addons plugin provided by hashthemes for all released versions up to and including 2.1.5.
Risk and Exploitability
With a CVSS score of 6.5 and an EPSS of < 1 %, the vulnerability is considered medium risk and not yet listed in CISA KEV. The likely attack vector is DOM‑based XSS through unfiltered input supplied to the plugin; the attacker needs only a web page that uses the plugin to compromise any visiting user’s browser.
OpenCVE Enrichment
EUVD