Impact
The vulnerability allows an authenticated attacker with contributor or higher privileges to store arbitrary JavaScript in the data-toggle-icon and data-close-icon attributes of the Navigation Menu Widget. Because the plugin fails to properly sanitise or escape these attributes, the attacker’s payload is rendered by the browser when a page using the widget is viewed. This type of flaw is a classic stored XSS (CWE‑79) and can compromise confidentiality, integrity, and availability by enabling script execution on behalf of unsuspecting users.
Affected Systems
The affected product is the Ultimate Addons for Elementor plugin from brainstormforce. All releases up to and including 2.9.1 contain the flaw. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score is 6.4, indicating a medium impact. The EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalogue. Attackers must be authenticated, so they need contributor‑level access or higher. Once logged in, they can store malicious code in content that will be served to other users, potentially leading to session hijacking, defacement, or data theft.
OpenCVE Enrichment