Impact
The vulnerability is a Cross Site Scripting flaw that allows an attacker to inject malicious client‑side scripts through the Element Pack Elementor Addons plugin when a user with content editing privileges submits specially crafted input. This defect is a classic input validation failure identified as CWE‑79. The injection can execute in the browsers of any visitor to the WordPress site, potentially leading to defacement, cookie theft, or phishing attacks. The potential consequences are limited to the affected site’s confidentiality, integrity, and availability, but there is no remote code execution or system compromise beyond the web application context.
Affected Systems
This defect affects the bdthemes Element Pack Elementor Addons plugin for WordPress, versions 8.8.3 and earlier. The published fix begins in version 8.8.4, which removes the vulnerable input handling. Site administrators should verify the plugin’s version and apply the latest update to prevent exploitation.
Risk and Exploitability
The CVSS score of 6.5 signals a medium‑severity risk. EPSS is not currently available, and the issue does not appear in the CISA KEV catalog, suggesting limited known exploitation. Based on the description, it is inferred that the attacker would need to use the plugin’s authoring interface or possess a privileged user role to insert malicious content, after which any site visitor will run the script.
OpenCVE Enrichment