Impact
The vulnerability arises from improper neutralization of input when generating web pages within the Ultimate Store Kit Elementor Addons plugin, enabling an attacker to inject malicious scripts that persist across sessions. The stored XSS can lead to theft of user credentials, session hijacking, or defacement of the site. The weakness is a classic input validation failure (CWE‑79).
Affected Systems
Affected systems are websites running bdthemes’ Ultimate Store Kit Elementor Addons plugin on WordPress, for all versions from the earliest release up through 2.5.0 inclusive.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1% suggests low likelihood of exploitation as of the last measurement. Because the vulnerability is not listed in the CISA KEV catalog, no known widespread exploitation is documented. Attackers would need to trick a user or gain access to submit vulnerable content, after which the malicious script would execute in the browser of any visitor that loads the affected page.
OpenCVE Enrichment
EUVD