Impact
WordPress sites that install the POSIMYTH The Plus Addons for Elementor Page Builder Lite plugin can be affected by a stored XSS vulnerability. The plugin fails to neutralize user input before rendering dynamic content, allowing an attacker to persist malicious scripts in the database. When an affected page is viewed, those scripts execute in the victim’s browser. Based on typical consequences of stored XSS, an attacker could potentially steal session cookies, hijack accounts, deface content, or inject additional exploit payloads, although these outcomes are inferred rather than documented in the CVE description.
Affected Systems
The vulnerability applies to WordPress installations that use the POSIMYTH The Plus Addons for Elementor Page Builder Lite plugin version 6.2.7 or earlier. No other products or versions are identified as impacted.
Risk and Exploitability
The EPSS score of < 1% suggests a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score of 6.5 indicates moderate impact if an attacker can write or edit content through the plugin’s interface. Because the flaw requires legitimate access to content creation tools, the attack surface is limited to sites that grant such privileges to users, but it remains advisable to address the weakness promptly.
OpenCVE Enrichment
EUVD