Impact
The Unlimited Elements For Elementor WordPress plugin, versions older than 2.0.11, fails to sanitize or escape data downloaded from the Google Serp API before rendering it in the plugin’s Google Reviews widget. As a result, attackers who submit a malicious review to a target business’s Google listing can embed JavaScript that will be stored and displayed to every user who views the widget. This stored cross‑site scripting can be used to steal session cookies, deface the site, or execute other client‑side attacks against site visitors, including privileged administrators.
Affected Systems
Any WordPress installation running the Unlimited Elements For Elementor plugin before release 2.0.11 and displaying the Google Reviews widget. The vulnerability is independent of WordPress user privileges and affects all pages that embed the widget.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑impact flaw, while the EPSS score of less than 1% suggests that, as of now, exploitation is considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers need to add a malicious review to the business’s Google listing; this is the inferred attack vector. Only the widget’s output is compromised, so the overall risk is high for page consumers but requires the attacker to influence the Google review feed.
OpenCVE Enrichment