Impact
The vulnerability is a DOM‑Based Stored Cross‑Site Scripting flaw triggered by the data‑gallery‑items parameter in the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin. Because the plugin does not properly sanitize or escape user input, an attacker can embed malicious JavaScript that is persisted in a gallery and executed in the browsers of any visitor to the affected page. This enables script execution in the context of the site, potentially leading to cookie theft, session hijacking, or defacement. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites using the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin from vendor wpdevteam, specifically any versions through 6.2.2. The vulnerability is present in all releases up to and inclusive of 6.2.2
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1 % suggests that exploitation is currently rare. Attackers need authenticated Contributor‑level access to inject the payload, and the injected code runs only when a user views the affected page, so the risk is mainly client‑side. The vulnerability is not listed in the CISA KEV catalog, and no publicly available exploit is documented.
OpenCVE Enrichment
EUVD