Impact
The vulnerability is an improper neutralization of input during web page generation (CWE-79), enabling attackers to inject malicious scripts that are stored in the site’s content. When a victim user loads the affected page, the injected code executes with the victim’s browser privileges, potentially allowing phishing, credential theft, or defacement.
Affected Systems
WordPress sites running hashthemes Easy Elementor Addons through version 2.2.5 are affected. The plugin’s input fields can store malicious payloads; no specific start version is given, but all releases up to 2.2.5 are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the current observation period. The vulnerability is not listed in CISA KEV. The likely attack vector is that attackers could use the plugin's admin or front-end form interfaces to supply malicious content; the payload then runs in the context of any visitor who loads the affected page.
OpenCVE Enrichment
EUVD