Impact
The Plus Addons for Elementor plugin stored the raw "custom_attributes" string from the Button widget into the database and later rendered it directly in the web page. Because the string passed through a bypassable filter, a contributor arbitrary Java would execute in the browsers of any visitor who loads the affected page, resulting in a stored cross‑site scripting flaw.
Affected Systems
WordPress installations that use the Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin versions up to and including 6.4.11 are affected. The vulnerability was fixed in version 6.4.12, which removes the vulnerable code path.
Risk and Exploitability
Exploitation requires authentication with at least Contributor privileges to inject the payload through the plugin's administration interface, but does not need prior compromise or external network exposure. Once stored, the malicious code runs automatically for all visitors to the page. The CVSS score of 6.4 represents moderate severity, and since the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, there is no current evidence of active exploitation, though the flaw remains viable.
OpenCVE Enrichment