Impact
The Exclusive Addons for Elementor plugin contains a stored cross‑site scripting flaw that allows an authenticated Contributor or higher to inject arbitrary scripts into the HTML attributes of the Countdown Timer widget. Those scripts execute whenever a visitor loads a page containing the affected widget, enabling the attacker to deface content, steal credentials, or redirect users to malicious sites.
Affected Systems
The vulnerability affects the Exclusive Addons for Elementor plugin for WordPress, versions up to and including 2.7.9.1. Any WordPress site that has this plugin installed and allows Contributor editors to add or edit pages can be impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity; the EPSS score of less than 1% suggests low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated and possess Contributor or higher privileges to exploit the flaw, but once exploited the injected scripts run in the context of site visitors, potentially compromising user data and trust.
OpenCVE Enrichment
EUVD