Impact
The vulnerability is an improper neutralization of user-supplied input during page rendering, which allows a stored Cross‑Site Scripting (XSS) flaw in the Black Widgets For Elementor plugin. An attacker who can inject malicious script content through the plugin’s UI would have the code executed in the browsers of anyone viewing the affected page. This could lead to defacement, cookie theft, session hijacking, or fully dropping a user context, thereby compromising confidentiality, integrity, and availability of the application for affected customers.
Affected Systems
The issue affects the Black Widgets For Elementor product from Modernaweb Studio, covering all releases through version 1.3.9.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s content administration interface, requiring authenticated access to inject the malicious payload. When a user subsequently views the stored content, the script executes in the browser, enabling the attacker to hijack the session or deface the site.
OpenCVE Enrichment
EUVD