Impact
The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker to inject and persist malicious JavaScript into web pages generated by the Atawai Gum Elementor Addon plugin. The bug results from improper neutralization of user input during page rendering, letting malicious code execute in visitors’ browsers when they view affected content. This can lead to session hijacking, credential theft, defacement, or malicious redirection, impacting confidentiality, integrity, and availability of site content.
Affected Systems
WordPress sites using the Gum Elementor Addon plugin from earlier releases through version 1.3.10 of products made by Atawai are vulnerable. Users who have not upgraded to a newer release are at risk.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity and the EPSS score of less than 1% suggests a low probability of exploitation, though the vulnerability is not listed in CISA KEV. The attack vector is inferred to be a web‑based web application vector, where attackers can inject code through plugin interfaces or configuration fields that the plugin stores and later renders.
OpenCVE Enrichment
EUVD