Impact
An improper neutralization of input during web page generation allows DOM‑based cross‑site scripting (XSS) in the News Element Elementor Blog Magazine plugin. This flaw means that an attacker can inject arbitrary JavaScript by crafting malicious input that the plugin then renders in the browser. The injected script could deface the site, steal session tokens, or redirect users to malicious sites.
Affected Systems
The vulnerability affects the webangon News Element Elementor Blog Magazine plugin for WordPress. All releases from the earliest available through version 1.0.9 are susceptible as the issue is present in all those iterations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated user who can submit crafted input via publicly accessible plugin fields, causing the victim’s browser to execute attacker‑controlled JavaScript when the content is displayed.
OpenCVE Enrichment
EUVD