Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through <= 1.3.10.
Published: 2025-03-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker to inject and persist malicious JavaScript into web pages generated by the Atawai Gum Elementor Addon plugin. The bug results from improper neutralization of user input during page rendering, letting malicious code execute in visitors’ browsers when they view affected content. This can lead to session hijacking, credential theft, defacement, or malicious redirection, impacting confidentiality, integrity, and availability of site content.

Affected Systems

WordPress sites using the Gum Elementor Addon plugin from earlier releases through version 1.3.10 of products made by Atawai are vulnerable. Users who have not upgraded to a newer release are at risk.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity and the EPSS score of less than 1% suggests a low probability of exploitation, though the vulnerability is not listed in CISA KEV. The attack vector is inferred to be a web‑based web application vector, where attackers can inject code through plugin interfaces or configuration fields that the plugin stores and later renders.

Generated by OpenCVE AI on May 1, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gum Elementor Addon to the latest version that removes the Stored XSS flaw.
  • If an upgrade cannot be performed immediately, disable the plugin until a patch is applied.
  • Review the site's database entries for the plugin to ensure no malicious script tags have been stored, and remove any that are present.

Generated by OpenCVE AI on May 1, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8376 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon allows Stored XSS. This issue affects Gum Elementor Addon: from n/a through 1.3.10.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon allows Stored XSS. This issue affects Gum Elementor Addon: from n/a through 1.3.10. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through <= 1.3.10.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon allows Stored XSS. This issue affects Gum Elementor Addon: from n/a through 1.3.10.
Title WordPress Gum Elementor Addon plugin <= 1.3.10 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.625Z

Reserved: 2025-03-26T09:20:18.315Z

Link: CVE-2025-30800

cve-icon Vulnrichment

Updated: 2025-03-27T13:59:08.504Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:41.017

Modified: 2026-04-23T15:27:05.693

Link: CVE-2025-30800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:15:08Z

Weaknesses