Impact
The vulnerability is a reflected Cross‑Site Scripting flaw caused by insufficient input neutralization when the Unlimited Elements For Elementor plugin renders user‑supplied data. An attacker who can influence input that will be displayed on the site can inject malicious JavaScript. When a victim accesses a URL or interacts with the page, the script runs in their browser, allowing credential theft, session hijacking, defacement, or other client‑side attacks.
Affected Systems
Unlimited Elements For Elementor (Free Widgets, Addons, Templates), a WordPress plugin. Versions up to and including 2.0.20 are affected; the recommended safe version is 2.0.21 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity flaw that can be exploited remotely over the web. The EPSS score is unavailable, so the exact attack probability is unknown, but reflected XSS is a common and well‑known technique. The vulnerability is not listed in CISA's KEV catalog. An attacker can trigger the flaw by crafting malicious URLs or inputs that are reflected in the page output, exploiting the lack of proper sanitization. The impact is limited to the compromised user session, not to the server itself.
OpenCVE Enrichment