Impact
The vulnerability is a DOM‑based cross‑site scripting flaw (CWE‑79). The plugin fails to neutralize user‐controlled input before it is reflected in the page, allowing an attacker to inject and execute arbitrary JavaScript when a victim views content that includes the plugin. This can lead to client‑side defacement or other malicious actions performed in the victim’s browser.
Affected Systems
Turbo Addons Elementor is the affected product. All releases up to and including version 1.7.7 are vulnerable. Any installation that has the plugin active is impacted, regardless of configuration settings.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by crafting input that the plugin incorporates into the page’s DOM, so the attack vector is the victim’s browser when loading a page that uses the plugin. Since the flaw is DOM‑based, it does not enable remote code execution on the server and requires only that the user’s session renders the vulnerable content.
OpenCVE Enrichment
EUVD