Impact
The UltraPress Ultra Addons Lite for Elementor plugin through version 1.1.8 contains a stored cross‑site scripting vulnerability caused by improper neutralisation of user input during web‑page generation. A malicious payload entered via the plugin’s interfaces will be embedded into the site’s HTML and executed whenever any visitor loads the affected content, potentially compromising the confidentiality and integrity of that visitor’s browser session.
Affected Systems
WordPress sites that install UltraPress Ultra Addons Lite for Elementor version 1.1.8 or earlier are affected. No specific component versions are listed beyond the plugin version itself.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % suggests low likelihood of exploitation at present. The vulnerability is absent from the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker with content‑editing privileges inserting malicious scripts via the plugin’s editor; it is inferred that any site visitor who views the manipulated content could be affected.
OpenCVE Enrichment
EUVD