Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting (XSS) flaw in StylemixThemes Consulting Elementor Widgets, affecting versions up to 1.4.2. An attacker can inject JavaScript payloads by manipulating data that the plugin incorporates directly into the rendered page, because the plugin fails to properly neutralize user input. The flaw is classified as CWE‑79.
Affected Systems
Any WordPress installation running the Consulting Elementor Widgets plugin from StylemixThemes with a version up to and including 1.4.2 is vulnerable. All deployments that employ this plugin, regardless of other themes or plugins, are impacted and must verify the installed version.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a low exploitation probability. The flaw is not listed in the CISA KEV catalog. Because the vulnerability is DOM‑based, it can be exploited by supplying manipulated data or a crafted URL; authentication is not required.
OpenCVE Enrichment