Impact
The Plus Addons for Elementor plugin allows a user with Contributor or higher privileges to store arbitrary JavaScript in the "custom_attributes" field of the Button widget. During rendering the plugin passes this raw input through a bypassable filter, resulting in a stored cross‑site scripting flaw that aligns with CWE‑79. An attacker can inject malicious code that executes in the browsers of every visitor to the affected page.
Affected Systems
WordPress sites that use The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin until and including version 6.4.11 are impacted. The flaw is resolved in 6.4.12.
Risk and Exploitability
Exploitation requires authenticated access with at least Contributor rights via the plugin's admin interface; no remote network entry is required. The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% coupled with the absence from the CISA KEV catalog suggests no current active exploitation has been observed, though the vulnerability remains viable.
OpenCVE Enrichment