Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to store malicious scripts in the site content. Stored XSS means the script is persisted and executed whenever a visitor loads the affected page, potentially leading to session hijacking, credential theft, or defacement. The flaw arises from the lack of output encoding for user supplied data.
Affected Systems
The weakness affects the "The Pack Elementor Addons" plugin by webangon, in all releases from the first version through version 2.1.1. No other vendors or product families are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at any given time. The vulnerability is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector involves an attacker submitting malicious input via the plugin’s content interface, which is then rendered without proper sanitization. Anyone with write access to content managed by the plugin could exploit this flaw, which could affect all site visitors.
OpenCVE Enrichment
EUVD