Impact
The vulnerability is a DOM‑based cross‑site scripting flaw caused by improper neutralization of user input when generating the plugin’s web page content. This flaw allows an attacker to inject arbitrary JavaScript that runs in the browser of any user who views a page containing the affected slider. The impact includes credential theft, session hijacking, defacement, or phishing of site visitors through malicious script execution.
Affected Systems
The HT Slider For Elementor plugin for WordPress, released by HT Plugins, is affected in all versions up through 1.6.5 (inclusive). The vulnerability applies to any WordPress site that installs this plugin at or below that version.
Risk and Exploitability
The CVSS score of 6.5 marks this as a moderate severity issue, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at the present time. The plugin’s public nature and the ability for attackers to craft a malicious link or payload mean that exposed users could be compromised, but the lack of a known exploit and low EPSS suggest that immediate risk is limited. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD