Impact
This vulnerability is a stored XSS flaw caused by improper neutralization of input during web page generation. An attacker can embed malicious JavaScript that is saved by the WordPress Premium Addons for Elementor plugin and executed on subsequent page loads, potentially allowing cookie theft, defacement, or redirection. The weakness is identified as a classic input‑validation issue (CWE‑79).
Affected Systems
The flaw affects the LeapWorx Premium Addons for Elementor WordPress plugin for all releases up to and including version 4.11.109. WordPress sites that have installed or enabled this plugin are impacted; no other vendors, products or versions are listed as affected.
Risk and Exploitability
The issue carries a CVSS score of 6.5, indicating moderate severity. No EPSS score is currently available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is a stored XSS, the likely attack vector requires an attacker to provide content that the plugin will render—this can be achieved by anyone who can edit Elementor blocks or settings, such as site administrators or editors. If the attacker succeeds, they can run arbitrary scripts in the context of site visitors, leading to credential theft or site defacement. While the exploit does not provide remote code execution on the server, the damage potential on the client side is significant and warrants prompt remediation.
OpenCVE Enrichment