Impact
A setting inside the Table widget of the Sina Extension for Elementor is inserted into an HTML attribute without proper escaping, creating a stored cross‑site scripting vector. Users assigned the Contributor role or higher can inject arbitrary JavaScript, which will execute in the browsers of any visitor who views the page containing the affected table. The vulnerability targets the output encoding process, making it an instance of input not properly neutralized during output rendering.
Affected Systems
The issue affects installations of the Sina Extension for Elementor WordPress plugin version 3.7.1 through 3.10.3. The application runs on WordPress sites that utilize the Table widget, and users with the Contributor role or higher are potentially able to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The requirement for a Contributor role or higher limits initial exploitation to users who already have elevated privileges on the affected WordPress installation. If an attacker is already compromised at that level, the stored XSS can be used to hijack user sessions or steal credentials for users who visit the page.
OpenCVE Enrichment