Impact
The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to a stored Cross‑Site Scripting flaw in the social URL parameter because the input is not properly sanitized and the output is not correctly escaped. Authenticated users with Contributor or higher privileges can inject arbitrary JavaScript, which will execute whenever a user accesses the affected page.
Affected Systems
WordPress sites running the RT Easy Builder – Advanced addons for Elementor plugin version 2.3 or earlier, provided by Risetheme. The vulnerability applies to all product releases up to and including 2.3.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk. The EPSS score of < 1% suggests that the likelihood of exploitation is low but non‑zero. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploitation is reported. Attackers must be authenticated with at least Contributor level access, which limits the potential threat vector to internal privileged users. The impact is limited to users who view the injected page.
OpenCVE Enrichment
EUVD