Impact
The CVE identifies an improper neutralization of input in WPDeveloper Essential Addons for Elementor that permits a stored Cross‑Site Scripting attack. An attacker can embed malicious script content that will be rendered in the browser when affected pages are viewed, allowing execution of arbitrary code in the user’s context.
Affected Systems
The flaw affects the Wordpress Essential Addons for Elementor plugin for all releases up to and including version 6.8.4. Versions 6.8.5 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. Likely exploitation requires an attacker to inject a payload via the plugin’s content interface, causing the script to execute for any user who accesses the affected page. The attack vector is inferred to involve site-side interaction with plugin content.
OpenCVE Enrichment