Impact
The vulnerability is a DOM‑based cross‑site scripting flaw that improperly neutralizes user input during web page rendering. An attacker can inject arbitrary JavaScript into pages rendered by the WPKoi Templates for Elementor plugin, potentially enabling session hijacking, defacement, or theft of user data.
Affected Systems
WordPress sites that have the WPKoi Templates for Elementor plugin installed, version 3.7.2 or earlier, developed by WPKoi WordPress Themes.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is considered medium severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation. The likely attack vector is user interaction with malicious content—such as a crafted URL or user‑supplied data that the plugin renders—allowing script execution in the victim’s browser. Although no public exploits are confirmed, the capacity for arbitrary code execution makes it a significant risk for exposed websites.
OpenCVE Enrichment