Impact
The WPBITS Addons For Elementor plugin contains a stored XSS vulnerability, classified as CWE-79. Insufficient sanitization of widget parameters allows authenticated users with contributor-level access to inject malicious scripts that run whenever someone visits a page containing the widget. An attacker can execute arbitrary JavaScript, potentially stealing session cookies, defacing the page, or launching further attacks.
Affected Systems
The affected product is the WPBITS Addons For Elementor Page Builder plugin for WordPress. Versions up to and including 1.8 are impacted. WordPress sites that have any of the vulnerable image_compare, text_rotator, or tooltip widgets enabled can be compromised by malicious content submitted through these widgets.
Risk and Exploitability
The CVSS score of 6.4 categorizes the flaw as moderate. The EPSS score is below 1%, indicating a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, so no widely used exploits are known. Attack vectors require a legitimate contributor-level or higher account to the WordPress administrative interface; once authenticated, the attacker can insert payloads into the vulnerable widget parameters that are stored and rendered to all visitors. The impact is primarily integrity and confidentiality of users within the site, with potential for defacement and session hijacking.
OpenCVE Enrichment