Impact
The Free Builder for Elementor plugin releases before version 1.6.7 fail to sanitize submitted contact form field values before storing them and later rendering them in the WordPress admin reach the public contact form to inject JavaScript that is stored in the database and executed when an administrator views the form submission, leading to stored XSS damage. The vulnerability is a classic input‑validation flaw identified as CWE‑79 and can result in execution of arbitrary scripts within the administrator’s browser context, potentially exposing confidential sitealing attacks.
Affected Systems
Any WordPress site that has the Free Builder for Elementor plugin installed at a version earlier than 1.6.7 is affected. The plugin is listed as an unknown free theme‑builder for Elementor; users should verify whether this plugin and its version number. Any site that still runs the vulnerable release should consider updating or removing the plugin until the fix is applied.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity and the EPSS score of less than 1% indicates that the likelihood of exploitation is currently very low, and it is not catalogued in the CISA KEV list. Nevertheless, the flaw is exploitable by unauthenticated attackers with access to the public contact form, which can be abused to inject payloads that run when an administrator views stored submissions. Because the attack vector is unprivileged, it is straightforward to craft malicious requests; the lack of output escaping in the admin interface allows the payload to execute in the admin browser, granting the attacker a high‑impact XSS vector.
OpenCVE Enrichment