Impact
The Make Column Clickable Elementor plugin improperly sanitizes user input that is stored in the database and used in page generation. As a result, an attacker who can add or edit a column can inject malicious JavaScript that will execute in the browsers of any visitor to the affected pages.
Affected Systems
WordPress installations that have the 'Make Column Clickable Elementor' plugin by Fernando Acosta, versions 1.6.0 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1 % suggests that the probability of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector would likely involve a user with privileges sufficient to configure columns within the plugin; the malicious payload is persisted and executed whenever the affected page is rendered for any user.
OpenCVE Enrichment
EUVD