Impact
The vulnerability arises from improper neutralization of input during web page generation, enabling a DOM‑based cross‑site scripting flaw in Best WP Developer BWD Elementor Addons. User‑supplied data can be injected into the page without adequate sanitization, allowing an attacker to execute arbitrary client‑side script. This flaw (CWE‑79) can lead to theft of credentials, defacement, or execution of malicious actions on behalf of the user.
Affected Systems
WordPress sites that have installed Best WP Developer’s BWD Elementor Addons plugin, version 4.4.2 or earlier, are affected. The weakness exists across all versions from the product’s inception up to and including 4.4.2.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows that the current probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to convince a victim to view a page that includes the vulnerable plugin’s output, which is typically performed via a crafted link or social‑engineering. While the impact remains client‑side, it can compromise confidentiality and integrity of user data on the target site.
OpenCVE Enrichment
EUVD