Impact
The News Kit Addons for Elementor plugin contains insufficient sanitisation of the Site Logo Title and Single Author Box widgets. This flaw, classified as CWE‑79, allows an authenticated attacker with contributor‑level access or higher to inject arbitrary JavaScript. The injected code is stored in the widget configuration and will execute whenever a user visits a page that renders the modified widget.
Affected Systems
All releases of the News Kit Addons for Elementor plugin from Blazethemes up to and including version 1.4.6 are vulnerable. The issue is specific to WordPress sites that use Elementor and employ the Site Logo Title and Single Author Box widgets.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity; the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor privileges who can intercept and modify the elementor_ajax AJAX save request to bypass client in the browsers of any visitor who views the affected widget, making the impact persistent across the site’s audience.
OpenCVE Enrichment