Impact
The SKT Addons for Elementor plugin is vulnerable to stored cross‑site scripting through multiple widgets because it fails to properly sanitize or escape user supplied attributes. For authenticated users with contributor-level privileges or higher, malicious code can be injected into page content that executes whenever other visitors load the affected page, allowing unintended script execution in the context of site visitors.
Affected Systems
All WordPress installations that use the SKT Addons for Elementor plugin, authored by sonalsinha21, and run any version up to and including 3.7 are affected. Users with contributor‑level or higher access are required to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk level. The EPSS score of less than 1% signals a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attack requires authenticated access with contributor privileges, making the threat conditional on user roles and site configuration.
OpenCVE Enrichment
EUVD