Impact
The Stratum – Elementor Widgets plugin contains a stored cross‑site scripting flaw driven by insufficient sanitization and escaping of user‑supplied widget attributes. A contributor‑level or higher attacker can inject arbitrary JavaScript that will run whenever a page containing the affected widget is rendered. This enables hijacking of other visitors’ sessions, defacement of the site, or leakage of sensitive data viewed by those users. The weakness is a classic input‑validation flaw and is identified by CWE‑79.
Affected Systems
All releases of the JetMonsters Stratum Widgets for Elementor plugin up to and including version 1.6.0 are vulnerable. The flaw appears in the Advanced Google Maps and Image Hotspot widgets and affects any site that has installed a vulnerable version of the plugin.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% shows low measured likelihood of exploitation at the time of analysis, and the issue is not listed in the CISA KEV catalog. However, because the attack can be executed by anyone with contributor‑level access, the risk is non‑trivial on sites where contributors are granted wide editing privileges. An attacker would need authenticated access to the WordPress back‑end, can then inject a payload via the widget settings, and the payload propagates to all visitors of pages containing the widget.
OpenCVE Enrichment
EUVD