Impact
The Gum Addon for Elementor plugin for WordPress contains a stored cross‑site scripting flaw in the pop_tag parameter. The plugin fails to properly validate or escape user‑supplied input, which allows an authenticated contributor or higher level user to embed arbitrary JavaScript into widget markup. When the page containing the widget is viewed, the injected script executes in the visitor’s browser, potentially stealing cookies, redirecting traffic, or delivering malware. The impact is primarily a compromise of confidentiality and integrity of users who access the affected page.
Affected Systems
The vulnerability affects the Gum Addon for Elementor plugin by celomitan. All versions up to and including 1.3.15 are impacted. Affected deployments are WordPress installations that have installed any of these plugin releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a medium severity. The EPSS score is less than 1 %, reflecting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor‑level privileges or higher, suggesting that the attack vector is an authenticated user action. Based on the description, it is inferred that an attacker must first obtain contributor rights or elevate existing rights, then input malicious code into the pop_tag setting of a widget.
OpenCVE Enrichment