Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. Attackers can inject malicious scripts that are saved in the plugin’s data, and when an end‑user loads the affected page, the script executes in the user’s browser. This can lead to session hijacking, credential theft, defacement, or other client‑side compromise. The issue is classified as CWE‑79 – an input validation weakness.
Affected Systems
The flaw affects the Xpro Elementor Addons plugin for WordPress, versions from the earliest available release through version 1.4.17 inclusive. Any WordPress installation using this plugin and not upgraded beyond 1.4.17 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high severity. The EPSS score of less than 1 % denotes that exploitation is considered unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker leveraging an input field in the plugin to embed a malicious payload that is stored and later rendered to users. Successful exploitation would require that a victim view the compromised page.
OpenCVE Enrichment
EUVD