Impact
The vulnerability in the Essential Addons for Elementor plugin allows authenticated users with Author-level or higher access to inject arbitrary JavaScript into event titles displayed by the Event Calendar widget. This occurs because the plugin does not properly sanitize and escape event titles sourced from The Events Calendar, enabling a stored cross‑site scripting flaw that is triggered whenever an affected event page is viewed.
Affected Systems
WordPress sites that have the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin installed in a version through 6.6.2 are affected. Only users with Author or higher privileges can inject malicious payloads, and all visitors to the compromised event page will execute the code.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity issue. The EPSS score of < 1 % signals that widespread exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authentication; after an author stores a malicious script in an event title, the payload remains persistent and is executed in each visitor’s browser whenever they view the event page, allowing attackers to run arbitrary client‑side code.
OpenCVE Enrichment