Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw in the Unlimited Elements For Elementor WordPress plugin, caused by insufficient input sanitization and output escaping of the 'data[name]' parameter; it allows an unauthenticated attacker to inject arbitrary JavaScript that executes in the victim’s browser context, potentially compromising confidentiality and integrity of user data.
Affected Systems
The affected product is the Unlimited Elements For Elementor plugin for WordPress; all versions up to and including 2.0.16 are vulnerable, regardless of additional WordPress themes or plugins.
Risk and Exploitability
With a CVSS score of 6.1, the vulnerability poses a moderate severity risk; the attack vector is unauthenticated, relying on the show_preview AJAX action accessible via a nonce that can be retrieved from any publicly available page, enabling attackers to trick users into clicking malicious links or visiting crafted URLs. The EPSS score is unavailable and the vendor has not yet listed the issue in CISA KEV, but the potential for widespread exploitation remains due to the ease of triggering the flaw.
OpenCVE Enrichment