Impact
The plugin suffers from unsanitized input handling in its Video Button and Countdown widgets. An authenticated contributor can insert arbitrary script code into widget attributes, which is stored and executed whenever any user views a page containing the widget.
Affected Systems
Jeg Elementor Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress, versions up to and including 2.6.12.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. With an EPSS score below 1%, exploitation attempts are unlikely but not impossible. The vulnerability is not listed in KEV, and requires authenticated access at the contributor level or higher. Once injected, the malicious script runs in the context of any user who views the affected page.
OpenCVE Enrichment
EUVD