Impact
The Elementor Website Builder plugin for WordPress is vulnerable to a stored cross‑site scripting flaw in the ‘elementor-element’ shortcode up to and including version 3.29.0. The flaw arises from insufficient input sanitization and output escaping on user‑supplied attributes, allowing an attacker who has contributor‑level or higher access to inject arbitrary JavaScript into page content. The injected scripts execute whenever any user views the affected page, potentially allowing cookie theft, session hijacking, or defacement. Only sites with Elementor’s ‘Element Caching’ enabled are impacted, as cached pages may persist the injected payload.
Affected Systems
WordPress sites running the Elementor Website Builder plugin, version 3.29.0 or earlier, that have Element Caching activated.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but it requires authenticated access at the contributor level or higher. Once exploited, the attacker can execute arbitrary code in the context of a victim’s browser, potentially compromising user sessions and site integrity.
OpenCVE Enrichment
EUVD