Impact
The Elements Plus! plugin for WordPress contains an insufficient sanitization and escaping flaw in the Image Comparison, HotSpot Plus, and Google Maps widgets, which allows an attacker who can post or edit content with contributor‑level or higher privileges to embed arbitrary JavaScript. When another user views the affected page, the injected code runs in the victim’s browser, potentially enabling session hijacking, defacement, or delivery of malware. This vulnerability is a classic stored cross‑site scripting flaw, classified as CWE‑79.
Affected Systems
All installations of the Elements Plus! plugin from the cssigniterteam, up to and including version 2.16.4, are affected. Any WordPress site running one of these versions with contributors or higher user roles has a vulnerability surface.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium‑to‑high risk. The EPSS score of < 1 % suggests that the likelihood of exploitation at this time is low, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires authenticated access with contributor or higher rights; an attacker submits malicious script through widget attributes, which is then stored and executed on subsequent page views by other site users.
OpenCVE Enrichment
EUVD