Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject arbitrary JavaScript into web pages generated by the LA‑Studio Element Kit for Elementor plugin. The stored payload can be executed in the browsers of any user who views the affected content, potentially leading to data theft, session hijacking, or defacement.
Affected Systems
The issue affects the LA‑Studio Element Kit for Elementor plugin from unspecified initial releases through version 1.5.1. The plugin is provided by LA‑Studio.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is of medium severity. The EPSS score of less than 1% indicates that exploitation is considered unlikely, and it is not listed in CISA’s KEV catalog. The likely attack vector is through an administrator or content editor submitting malicious data into plugin fields, which is then rendered to all visitors. The stored nature of the flaw means that any user who views the content can be impacted.
OpenCVE Enrichment
EUVD