Impact
The vulnerability originates from improper neutralization of user input during web page generation in the StylePress for Elementor full‑site‑builder‑for‑elementor plugin. It permits an attacker to embed malicious script content that is stored and later executed in browsers of users who view affected pages. The resulting Stored XSS can enable theft of credentials, session hijacking, defacement, or further malware delivery. The weakness is a typical input‑validation flaw identified as CWE‑79.
Affected Systems
The flaw affects the dtbaker StylePress for Elementor plugin in any version up through 1.2.1. Any WordPress site that has installed this plugin at version 1.2.1 or older is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a browser‑based injection performed by an attacker who can submit content that will be stored and later rendered, with no special authentication beyond access to the site’s content management functionality. Given the moderate severity and low likelihood of exploitation, the overall risk is moderate but bounded by a low exploit probability.
OpenCVE Enrichment
EUVD