Impact
Improper Neutralization of Input During Web Page Generation is identified in the Xpro Elementor Addons plugin, resulting in a DOM‑Based XSS flaw that allows attackers to inject and execute arbitrary scripts in the browsers of visitors to the affected site. This can lead to disclosure of sensitive data, session hijacking, or further client‑side attacks. The weakness is categorized as CWE‑79, indicating a lack of sufficient input validation or output encoding.
Affected Systems
The vulnerability affects the Xpro Elementor Addons WordPress plugin distributed as Xpro Elementor Addons through version 1.4.19.1, with no later versions listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity level, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed as part of a coordinated exploitation campaign. The most likely attack vector is through any user‑controllable input that the plugin does not properly sanitize during DOM construction; this inference is drawn from the description of a DOM‑Based XSS scenario.
OpenCVE Enrichment