Impact
The Grand Restaurant Theme Elements for Elementor plugin has a stored cross‑site scripting vulnerability. The plugin does not properly neutralize user‑supplied data when generating web pages, which can allow an attacker to save malicious scripts into the site and serve them to any visitor. This allows malicious scripts to run in the browsers of users who view the affected pages.
Affected Systems
The vulnerability affects ThemeGoods’ Grand Restaurant Theme Elements for Elementor plugin as used on WordPress sites. Versions up to and including 2.1.1 are impacted. Any site that has installed the plugin version 2.1.1 or earlier is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves inserting malicious content via the plugin’s editor or configuration sections that are not filtered before rendering, and requires write access to the site’s theme settings.
OpenCVE Enrichment