Impact
The Style Kits – Advanced Theme Styles for Elementor plugin allows an authenticated user with contributor-level access or higher to inject arbitrary JavaScript into the kit title field via the "/wp-json/agwp/v1/tokens/save" endpoint. This input is stored and later rendered in an admin attribute context without proper sanitization or escaping, enabling stored cross‑site scripting that will run whenever a user views an injected page. The flaw could be used to deface content, steal session cookies, or hijack user sessions, impacting confidentiality, integrity, and availability of the site.
Affected Systems
WordPress sites that have the analogwp Style Kits for Elementor plugin installed in versions 2.5.0 and earlier.
Risk and Exploitability
The flaw has a CVSS score of 6.4, indicating a moderate severity vulnerability. The EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. The likely attack vector is the authenticated application layer, requiring a user with contributor privileges; the exploit does not require network-level access or elevated OS privileges.
OpenCVE Enrichment