Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows attackers to store malicious scripts within the WordPress site via the Ultimate Store Kit Elementor Addons plugin. Stored XSS is the primary impact, enabling the attacker to run arbitrary JavaScript in the browsers of any visitor to the compromised site. This can lead to session hijacking, credential theft, defacement, or the delivery of malware, affecting the confidentiality, integrity, and availability of the site and its users. The weakness is indexed as CWE‑79 – a classic input‑validation issue.

Affected Systems

This issue affects the bdthemes Ultimate Store Kit Elementor Addons plugin for WordPress. Any installation of the plugin with a version number of 2.8.6 or earlier is vulnerable. The plugin is used to add e‑commerce and Elementor extensions to WordPress sites. Users running these affected plugin versions should consider their installation at risk.

Risk and Exploitability

The CVSS score of 6.5 places the flaw in the Medium severity range, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation typically requires the attacker to inject malicious code into a content field that is later rendered by the plugin. This could be achieved through the WordPress admin interface or via any form that stores user‑supplied content. Once the script is stored, any visitor to the affected page will execute it, providing a straightforward attack path for attackers who can write to the site’s content.

Generated by OpenCVE AI on April 30, 2026 at 06:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ultimate Store Kit Elementor Addons plugin to version 2.8.7 or later
  • Disable or uninstall the plugin if it is not required for site functionality
  • Review and remove any stored content that may contain malicious scripts, and validate that the site no longer renders such content

Generated by OpenCVE AI on April 30, 2026 at 06:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30628 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.8.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.8.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6.
Title WordPress Ultimate Store Kit Elementor Addons Plugin <= 2.8.2 - Cross Site Scripting (XSS) Vulnerability WordPress Ultimate Store Kit Elementor Addons plugin <= 2.8.6 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes utlimate Store Kit Elementor Addons
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes utlimate Store Kit Elementor Addons
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.8.2.
Title WordPress Ultimate Store Kit Elementor Addons Plugin <= 2.8.2 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Bdthemes Utlimate Store Kit Elementor Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:29:20.127Z

Reserved: 2025-08-22T11:37:50.459Z

Link: CVE-2025-58017

cve-icon Vulnrichment

Updated: 2025-09-23T15:41:04.958Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:03.740

Modified: 2026-04-23T15:33:14.693

Link: CVE-2025-58017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:45:16Z

Weaknesses