Impact
The Exclusive Addons for Elementor plugin contains a stored cross‑site post title is set or modified. The plugin fails to sanitize or escape the title value before storing or rendering it, which allows an attacker to embed arbitrary JavaScript that will execute in the browser of any user who views the affected post. The weakness is classified. The exploited script runs on the client side and can perform, such as modifying page content or capturing information that the browser can access. No server‑side side effects CVE details.
Affected Systems
All installations of Exclusive Addons for Elementor version 2.7.9.8 or earlier, maintained by timstrifler, are affected. The plugin is used within WordPress sites. The vulnerability is only exploitable by users who have Contributor‑level or higher permissions.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is less than 1 %, suggesting that exploitation is expected to be rare, but a valid account with Contributor access is required for the attack. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by creating or editing a post with a malicious title; the payload who opens that post.
OpenCVE Enrichment