Impact
An unauthenticated Cross Site Scripting vulnerability exists in the WordPress "Blog, Posts and Category Filter for Elementor" plugin versions 2.1.0 and earlier. The flaw allows an attacker to embed malicious JavaScript code via the plugin’s inputs. Once executed, the script runs with the privileges of the page visitor and can steal credentials, deface content, or hijack user sessions. The CWE-79 weakness indicates improper sanitization of user‑supplied data.
Affected Systems
Any WordPress site that has the "Blog, Posts and Category Filter for Elementor" plugin installed at version 2.1.0 or earlier is affected. The plugin, developed by Plugin Devs, is widely used to manage blog posts, pages, and categories through Elementor. No other WordPress core components are directly implicated.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity, reflecting medium to high impact and reasonable ease of exploitation. EPSS data is not available, so the public exploitation likelihood cannot be precisely quantified, but the lack of an authentication requirement and the ability to inject arbitrary scripts elevate the threat. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation at the time of reporting. Attackers would most likely exploit the flaw via a crafted URL or link that includes malicious input processed by the plugin’s filter routines.
OpenCVE Enrichment