Impact
An attacker can inject arbitrary JavaScript into pages rendered by the Musician's Pack For Elementor plugin due to improper neutralization of input. This DOM‑Based XSS can lead to session hijacking, defacement, or distribution of malware, compromising confidentiality and integrity of user data for any visitor to a compromised site. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
WordPress installations that have the Musician's Pack For Elementor plugin version 1.8.7 or earlier are vulnerable. Users of any site using this plugin up to the specified release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA KEV, but due to the widespread use of WordPress plugins and the nature of DOM‑Based XSS, it remains a significant threat. Likely attack vectors include placing malicious payloads in user‑visible fields that the plugin then exposes unfiltered within the browser.
OpenCVE Enrichment
EUVD