Impact
The vulnerability is a stored cross‑site scripting flaw caused by insufficient input sanitization in the WP Smart Widgets’ Better Post & Filter Widgets for Elementor plugin. Attackers can inject malicious HTML or JavaScript that is saved to the site and executed when any user loads the vulnerable content. This failure to neutralize user input falls under CWE‑79 and can lead to defacement, credential theft, or session hijacking for visiting users.
Affected Systems
The flaw affects all releases of the Better Post & Filter Widgets for Elementor plugin from the initial version up through and including version 1.6.1. The plugin is distributed by WP Smart Widgets.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate. The EPSS score of less than 1 % indicates a very low likelihood of exploitation at the time of reporting, and the issue is not listed in the CISA KEV catalog. Exposures occur when an attacker injects malicious content via a trusted editing interface; any subsequent visitor to the compromised page becomes a victim, making the impact effectively remote.
OpenCVE Enrichment
EUVD