Impact
A contributor cross‑site scripting flaw exists in the Ultimate Store Kit Elementor Addons plugin for WordPress, affecting all releases up to version 3.0.5. The vulnerability allows arbitrary JavaScript code to be injected into web pages viewed by site visitors, potentially enabling session hijacking, data theft, or defacement. The weakness is formally classified as CWE‑79.
Affected Systems
WordPress sites that have installed the bdthemes Ultimate Store Kit Elementor Addons plugin version 3.0.5 or earlier are affected. No other vendors or product lines are noted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1 % reflects a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker would need to submit malicious content through plugin inputs, implying the attack vector is likely through trusted contributor or administrator roles if access controls are lax. Proper input validation or filtering is missing, making exploitation feasible if such input channels are available.
OpenCVE Enrichment