Impact
The LA‑Studio Element Kit for Elementor plugin for WordPress contains a stored cross‑site scripting flaw that arises when the Image Compare and Google Maps widgets are used. The plugin fails to sanitize or escape user‑supplied attributes, allowing an authenticated attacker with contributor‑level access to inject arbitrary JavaScript that will execute for every visitor to the affected page. This can lead to session hijacking, data theft, or defacement, impacting the confidentiality, integrity, and availability of site content for all users who view the compromised pages.
Affected Systems
WordPress sites using the LA‑Studio Element Kit for Elementor plugin version 1.5.2 or earlier are vulnerable. The vulnerability is present in all releases up to and including 1.5.2 and affects both the Image Compare widget and the Google Maps widget integrated into the plugin.
Risk and Exploitability
The CVSS v3.1 score of 6.4 indicates a moderate severity. The EPSS score is below 1%, suggesting that the overall exploitation probability is low, and the vulnerability is not yet listed in the CISA KEV catalog. However, the flaw requires only authenticated contributor‑level access, which is a relatively low privilege threshold on many WordPress sites. Attackers could leverage compromised editor accounts or social engineering to gain such access, after which injected scripts would be presented to any visitor of affected pages, creating a widespread impact across all users of the affected site.
OpenCVE Enrichment
EUVD