Impact
Sky Addons for Elementor is vulnerable to stored XSS in all releases up to and including 3.1.4 because the plugin does not properly sanitize or escape user‑supplied widget attributes. An authenticated user with contributor or higher privileges can inject arbitrary JavaScript into a page, which will then run automatically for any visitor who loads that page. This flaw, classified as CWE‑79, allows the attacker to hijack user sessions, deface content, or spread malware via the site’s public-facing pages.
Affected Systems
The vulnerability affects the WordPress plugin Sky Addons – Elementor Addons with Widgets & Templates, specifically all versions up to 3.1.4. Sites running this plugin without updating to a newer release are exposed.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not included in the CISA KEV catalog. The attack requires authentication with at least contributor level, making the vector internal. However, once exploited, malicious scripts execute on every page load by any user, potentially compromising confidentiality, integrity, and availability for all visitors to the affected site.
OpenCVE Enrichment
EUVD