Impact
A stored Cross‑Site Scripting flaw exists in the Progress Bar shortcode of the plugin, stemming from inadequate sanitization and escaping of user supplied attributes. An attacker with contributor‑level or higher authenticated access can inject malicious scripts that run whenever a page containing the shortcode is viewed, potentially compromising site content and user interactions.
Affected Systems
The vulnerability affects the WordPress plugin "The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce" developed by posimyththemes. All releases up to and including version 6.4.9 are impacted; versions newer than 6.4.9 are presumed untainted.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. While the Exploit Prediction Scoring System score is not available and the vulnerability is not listed in the CISA KEV catalog, the requirement for authenticated contributor or higher access indicates that exploitation is likely limited to site administrators or privileged users. The altered scripts could lead to theft of credentials, defacement, or further lateral movement within the site.
OpenCVE Enrichment