Impact
Improper Neutralization of Input During Web Page Generation (XSS) is present in the K Elements plugin for WordPress. The flaw is DOM‑based and allows an attacker to inject arbitrary JavaScript into pages rendered by the plugin. When users view those pages, the browser will execute the injected script, potentially compromising the confidentiality and integrity of user data and the site’s operation.
Affected Systems
The vulnerability affects the SeventhQueen K Elements WordPress plugin in all releases prior to version 5.5.0. Any WordPress site that has the plugin installed and contains elements rendered by the vulnerable code is at risk. The core WordPress installation is not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% signals a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The description identifies the issue as a DOM‑based XSS, meaning that an attacker must supply or influence content that passes through the plugin’s rendering logic. No explicit privilege requirements are documented in the CVE data.
OpenCVE Enrichment