Impact
The Borderless – Addons and Templates for Elementor plugin contains a stored Cross‑Site Scripting flaw. The title field of several widgets is not properly sanitized or escaped, so an authenticated user with Contributor or higher privileges can submit JavaScript that is persisted in the database. When any visitor loads the affected page, the malicious script runs in their browser, potentially hijacking sessions, defacing content, or facilitating phishing attempts.
Affected Systems
Borderless – Addons and Templates for Elementor (visualmodo) versions 1.7.1 and earlier are affected.
Risk and Exploitability
The CVSS score of 6.4 classifies the issue as medium severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation as of the latest data. This vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated Contributor‑level access, and the exploitation is limited to clients viewing the injected page. The impact is primarily client‑side code execution rather than server‑side compromise or remote code execution.
OpenCVE Enrichment
EUVD