Impact
The vulnerability allows an authenticated user with contributor or higher privileges to inject malicious script code through the Reading Progress Global Color Settings feature. Because the input is not sanitized or properly escaped, the injected payload is stored and later delivered to other users when they view pages that use the global color configuration, enabling cross‑site scripting attacks. The impact is execution of arbitrary scripts in the context of site visitors, potentially leading to data theft, session hijacking, or distribution of further malware. This flaw is classified as CWE‑79.
Affected Systems
The issue applies to the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress in all releases up to and including version 6.6.11. Versions 6.7.0 and later contain the patch that removes the vulnerability.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium‑to‑high severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in CISA's KEV catalog, reducing immediate threat awareness. Attackers would need authenticated contributor-level access to the WordPress site and would typically use the global color settings panel to persist malicious script code. Once a user opens a page that includes the compromised color setting, the script runs in that user's browser, allowing the attacker to steal session cookies or carry out other client‑side attacks.
OpenCVE Enrichment