Impact
The vulnerability resides in the Unlimited Elements For Elementor plugin for WordPress. Insufficient input sanitization and output escaping in several widgets allow an authenticated attacker with Contributor role or higher to embed arbitrary JavaScript. When an injected page is viewed, the script runs in the victim’s browser, enabling cookie theft, session hijack or site defacement.
Affected Systems
This flaw affects all installations of Unlimited Elements For Elementor up to and including version 1.5.148 on WordPress sites. Administrators should verify the plugin version used and consider an upgrade if newer releases are available.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate severity. The EPSS score of < 1 % means that the probability of exploitation is very low at present, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first acquire Contributor‑level access to the site; legitimate users of that role can then edit pages or widgets to inject the malicious code. Successful exploitation results in client‑side scripting that can target any visitor of the affected page.
OpenCVE Enrichment
EUVD