Impact
This vulnerability is a stored cross‑site scripting flaw in the Elementor WordPress plugin, present in all releases up to and including 3.30.2. The flaw originates in the data‑text DOM element attribute of the Text Path widget, which the plugin fails to sanitize or escape. An attacker with Contributor‑level or higher privileges can inject arbitrary JavaScript that is stored as part of a page. When another visitor opens that page in Chrome or Edge, the script executes in the victim’s browser. The impact is collection of user credentials, cookie theft, defacement or further compromise of the site’s content.
Affected Systems
Any WordPress site that has the Elementor plugin installed with a version 3.30.2 or earlier is affected. This includes all deployments of the Elementor Website Builder plugin that have not applied the latest update.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating a moderate severity. The EPSS score is below 1 %, meaning the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must first obtain Contributor‑level access, the real‑world risk requires authenticated exploitation. The script is limited to Chrome and Edge browsers, reducing the scope of affected users.
OpenCVE Enrichment
EUVD