Impact
The Exclusive Addons for Elementor plugin stores user-supplied input from the exad_infobox_image field without validation or proper output escaping. Authenticated users with Contributor or higher capability can insert arbitrary JavaScript; when the impacted infobox is rendered, the injected code executes in the context of all visitors who view that page, enabling session hijacking, credential theft, or defacement.
Affected Systems
The vulnerability exists in all releases of the Exclusive Addons for Elementor plugin up to and including version 2.7.9.8. Any WordPress site that installs or updates to a version in this range and uses the infobox element exposes the stored exploit.
Risk and Exploitability
With a CVSS score of 6.4 the weakness is considered moderate severity, and the EPSS score of less than 1 percent indicates a low probability of active exploitation in the wild. The attack path requires authenticated access with Contributor or higher capability; once injected, the payload persists until the infobox content is edited. The vulnerability is not listed in the CISA KEV catalog, and the advisories do not mention a patched release, suggesting that newer plugin versions are required for a full fix.
OpenCVE Enrichment