Impact
The vulnerability is an improper neutralization of input during web page generation that permits Stored XSS. Malicious scripts injected through unfiltered plugin data can execute in a victim’s browser, potentially stealing cookies, hijacking sessions, defacing content, or deflecting traffic to malicious sites. The weakness is classified as CWE‑79.
Affected Systems
The issue affects the Tim Strifler Exclusive Addons Elementor plugin. All releases from the earliest available version up to and including version 2.7.9 are impacted.
Risk and Exploitability
The CVSS score is 5.9, indicating a medium severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation at present. Based on the description, the attacker likely needs access to a form or content editor that accepts data for the plugin, making the attack vector local to users who can create or edit plugin‑related content. The impact is confined to those visitors who load the affected pages but can lead to credential theft or session hijack if the injected script runs in a user’s browser.
OpenCVE Enrichment
EUVD