Impact
The vulnerable plugin fails to validate the title tag of its Pricing Table widget, which permits users with Contributor or higher roles to embed arbitrary JavaScript. Once the malicious title is stored, the script runs whenever the page is rendered, putting visitors—especially administrators who preview or view the post—at risk of session hijacking or data theft.
Affected Systems
Essential Addons for Elementor for WordPress, versions prior to 6.6.10. Administrators and contributors using sites that have installed these releases are susceptible.
Risk and Exploitability
This flaw carries a CVSS score of 4.8, indicating moderate severity. The EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalog. If a Contributor can create or edit a pricing table, the stored XSS can be triggered by any user who visits the affected page, including site administrators.
OpenCVE Enrichment