Impact
The Medical Addon for Elementor plugin for WordPress contains a stored cross‑site scripting vulnerability that affects the Typewriter widget in all releases up to and including 1.6.4. The flaw arises from insufficient input sanitization and output escaping of user‑supplied attributes, allowing an authenticated user with contributor privileges or higher to inject arbitrary JavaScript that will execute whenever an affected page is viewed.
Affected Systems
The affected product is the WordPress plugin Medical Addon for Elementor produced by nicheaddons. All plugin versions from the initial release through 1.6.4 are vulnerable. Users who have installed any of these versions should verify whether the Typewriter widget is active on their sites.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity flaw. The EPSS score of less than 1 % suggests a low likelihood of community exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated contributor access, exploitation is limited to users with elevated privileges, reducing the risk from anonymous attackers but still presenting a threat to sites that grant broad contributor permissions.
OpenCVE Enrichment
EUVD