Impact
The MarqueeAddons plugin for WordPress contains a stored Cross‑Site Scripting flaw in its Testimonial Marquee widget across all versions up to and including 2.4.3. Input provided by users is not properly sanitized or escaped, enabling an authenticated contributor or higher to embed arbitrary scripts into the widget. These scripts execute for every visitor who loads a page containing the malicious widget, allowing the attacker to run code in the users' browsers.
Affected Systems
DebuggersStudio’s Marquee Addons for Elementor – Essential Motion Widgets & Templates. Versions 2.4.3 and earlier are affected. All earlier releases share the same widget implementation, so they are likewise vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is below 1%, suggesting a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers must have contributor‑level or higher credentials to inject the payload; once injected, the malicious scripts run for all site visitors who view pages containing the widget. The impact is limited to the affected WordPress site and depends on the widget being displayed on publicly viewable content.
OpenCVE Enrichment