Impact
The AdForest Elementor plugin contains an input neutralization flaw that permits reflected cross‑site scripting. When a vulnerable page displays data supplied by a visitor, the unsanitized input is returned directly to the browser, allowing a malicious script to be executed in the victim’s context. The weakness is a classic reflected XSS, classified as CWE‑79, and can enable an attacker to run arbitrary JavaScript for users who view the crafted page.
Affected Systems
All WordPress sites that installed the AdForest Elementor plugin with a version numbered 3.0.11 or earlier are affected. This includes any deployment using the plugin from its initial release up to, and including, version 3.0.11. Administrators should confirm the active plugin version and determine whether their installation falls within the vulnerable range.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this web‑application flaw. The EPSS score of < 1 % suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to provide a crafted URL or form input that triggers the plugin to echo the malicious payload; the script then runs in the visitor’s browser. No publicly available proof‑of‑concept or active exploit has been reported.
OpenCVE Enrichment