Impact
The ShopEngine Elementor WooCommerce Builder Addon is vulnerable to a stored cross‑site scripting flaw that occurs when the 'shopengine_product_title_header_size' parameter is not properly sanitized or escaped. Authenticated users who hold an Author role or higher can insert arbitrary JavaScript into that parameter, and the injected script is stored and rendered on product pages. Executed scripts run in the context of site or defacement.
Affected Systems
All WordPress installations that use the ShopEngine Elementor WooCommerce Builder Addon of version 4.9.5 or earlier are affected. The vulnerability exists in the plugin component that processes the 'shopengine_product_title_header_size' field, and no other product versions have been confirmed to be impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and an EPSS score of < 1% indicates a very low but nonzero exploitation probability. The issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to have authenticated author‑level access to the site, after which they can inject malicious scripts via the vulnerable parameter. Once injected, the scripts execute automatically for any visitor who loads the affected product page, making the risk persistent and potentially widespread.
OpenCVE Enrichment