Impact
The vulnerability involves improper neutralization of input during page generation, resulting in a DOM‑based XSS. This can allow an attacker to execute arbitrary JavaScript in the context of a victim’s browser, potentially leaking sensitive information or performing actions on behalf of the user. The weakness maps to CWE‑79.
Affected Systems
The issue affects the Wealcoder Animation Addons for Elementor plugin. All releases from the earliest available version up to and including 2.6.1 are impacted. Site owners running any of these versions on WordPress should consider the plugin a potential vector for exploitation.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity. The EPSS score is under 1 %, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is likely possible by any actor who can load a page that includes the plugin’s output, such as through a crafted URL or by persuading a user to view a malicious link. No authentication is required, and the attack can be performed entirely from the victim’s browser.
OpenCVE Enrichment