Impact
The vulnerability is an improper neutralization of input during web page generation in the HT Mega – Absolute Addons for WPBakery Page Builder WordPress plugin. It permits stored XSS where attacker‑supplied data is stored and later rendered in the browser context of any user who views the affected content, enabling malicious script execution in the victim’s browser.
Affected Systems
HT Mega – Absolute Addons for WPBakery Page Builder plugin installations on WordPress sites running version 1.0.8 or earlier are affected. All releases up to and including 1.0.8 contain the flaw, as the plugin has not applied the necessary input sanitization in those versions.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply malicious input that the plugin stores and later renders; the likely attack vector involves submitting data through administrative forms or other front‑end features that accept user content. Once inserted, the payload executes when the stored data is displayed, enabling session hijacking or other client‑side compromises.
OpenCVE Enrichment
EUVD