Impact
The vulnerability is a stored cross‑site scripting flaw due to improper neutralisation of user input during page rendering. An attacker can inject malicious script payloads that are persisted by the plugin and executed in the browsers of any user who views the affected content.
Affected Systems
The WordPress plugin Responsive Addons for Elementor from CyberChimps, for all versions up to and including 1.7.3.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw. The EPSS score is less than 1%, implying that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to provide content that is stored by the plugin (e.g., via the Elementor editor) and then have that content accessed by a victim device.
OpenCVE Enrichment
EUVD