Impact
The Vulnerability is a reflected Cross‑Site Scripting flaw where user supplied data is re‑inserted into an unauthenticated AJAX response without escaping. An attacker can craft a URL that causes the victim’s browser to execute arbitrary JavaScript when the victim accesses it. The weakness is identified as CWE‑79 and can be leveraged for content theft, session hijacking, or phishing attacks in the victim’s session.
Affected Systems
The affected product is the Sina Extension for Elementor WordPress plugin. All releases prior to version 3.10.2 are vulnerable. The vendor is unknown but the plugin is identified in the WordPress repository.
Risk and Exploitability
With a CVSS score of 6.1 the vulnerability is considered moderate severity. The EPSS score is reported as < 1 % (approximately 0.00162), indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the KEV catalog. The vulnerability can be exercised via a simple unauthenticated AJAX call, so a remote attacker can trigger the exploit from any internet‑connected site that includes the plugin or directs a user there. The risk is present for all WordPress sites that have the vulnerable plugin installed and have the AJAX endpoint exposed.
OpenCVE Enrichment