Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting (XSS) flaw in the ElementInvader Addons for Elementor plugin. Unsanitized user input is included in generated HTML, allowing an attacker to inject and execute arbitrary JavaScript in the context of the site. This can lead to cookie theft, session hijacking, defacement or delivery of additional malware to visitors. The flaw does not provide remote code execution but affects the confidentiality and integrity of users who interact with the affected pages.
Affected Systems
The flaw affects the ElementInvader:ElementInvader Addons for Elementor plugin, version 1.4.3 and earlier. WordPress sites that have installed any of these versions and use the plugin are impacted; the impact occurs entirely in the client browsers.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity, the EPSS score indicates a low exploitation probability (< 1%), and the KEV status is not listed. It triggers the XSS when the page loads, potentially affecting any affected component. The attack vector is client‑side and does not require privileged access to the server. Because the flaw is DOM‑based, exploitation is limited to the browser environment, but it can still be highly damaging to user data and the site’s reputation.
OpenCVE Enrichment