Impact
The WPSHARE247 Elementor Addons plugin has a stored XSS flaw that allows an attacker to inject malicious JavaScript that is executed in the browser of any user who views the affected content. The improper neutralization of user input can lead to session hijacking, credential theft, or defacement, compromising confidentiality and integrity.
Affected Systems
WordPress installations that have the WPSHARE247 Elementor Addons plugin version 2.5 or earlier from Website366.com are affected. The vulnerability applies to all releases from the earliest available version through <= 2.5.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1% shows a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to find a way to inject malicious content into the plugin’s storage, which is inferred from the stored XSS description. Once deployed, the attack would affect all site visitors.
OpenCVE Enrichment
EUVD