Impact
The vulnerability is a stored cross‑site scripting flaw in Premium Addons for Elementor. Input from the 'premium_tooltip_text' field is not sanitized or escaped, allowing an authenticated user with contributor or higher privileges to inject arbitrary scripts that are rendered in the Elementor editor via the print_template() hook.
Affected Systems
All WordPress sites that install the Premium Addons for Elementor plugin version 4.11.84 or earlier are vulnerable. Versions before 4.11.84 are impacted because validation logic is fixed only in later releases. Sites that rely on the plugin for tooltips or related widget functionality are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 4.9, indicating moderate severity, and an EPSS score of less than 1 %, implying a low likelihood of exploitation. It is not yet catalogued in the CISA KEV list. Exploitation requires an authenticated contributor‑level or higher account and relies on the attacker opening an affected post in the Elementor editor; therefore the attack vector is limited to the administrative back‑end rather than the public front‑end. Given the low probability score, the immediate threat is moderate but remains significant for sites with highly privileged user roles.
OpenCVE Enrichment