Impact
The Anber Elementor Addon plugin for WordPress contains a stored cross‑site scripting flaw that allows an authenticated Contributor or higher to inject malicious scripts into the carousel button link. The injected payload or script is stored in the database and rendered on any page that displays the carousel, enabling an attacker to run arbitrary JavaScript in the browsers of all users who view the affected page.
Affected Systems
WordPress sites that have the Anber Elementor Addon installed and are running any version up to and including 1.0.1 are susceptible. Users with Contributor level or higher access can exploit the flaw through the plugin’s admin interface.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers need only legitimate contributor credentials and access to the plugin’s UI to store the malicious script, after which any visitor to the compromised page will execute the payload.
OpenCVE Enrichment
EUVD