Impact
The Easy Elementor Addons plugin contains a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject or execute arbitrary client‑side scripts when a user visits an affected page. This can lead to theft of session cookies, defacement of the site, or redirection to malicious domains. The weakness is identified as CWE‑79. No mention of privilege escalation or server‑side compromise is made in the description.
Affected Systems
The vulnerability affects the Easy Elementor Addons plugin released by hashthemes. All versions up to and including 2.2.6 are vulnerable; the text states "from n/a through <= 2.2.6", indicating that any release before or equal to 2.2.6 is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack requires a user to load a page containing the vulnerable code, with no special authentication or privilege needed. An attacker could embed malicious JavaScript through crafted URLs or injected content, leading to XSS execution in the victim's browser.
OpenCVE Enrichment
EUVD