Impact
Improper neutralization of user input during page generation allows a DOM‑based Cross‑Site Scripting (XSS) flaw to be injected. An attacker can craft malicious JavaScript that will run in the browser of any visitor to a vulnerable page, potentially stealing session cookies or performing other client‑side attacks.
Affected Systems
The vulnerability affects the WordPress plugin WPKoi Templates for Elementor (wpkoithemes:WPKoi Templates for Elementor) for all versions up to and including 3.4.3. Sites that have installed the plugin in these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation currently. The flaw is client‑side (DOM‑based) and does not require authentication, meaning any user who visits a maliciously crafted page can be impacted. The vulnerability does not appear in the CISA KEV catalog.
OpenCVE Enrichment
EUVD