Impact
The aThemes Addons for Elementor plugin is vulnerable to stored cross‑site scripting through the 'title_tag' widget setting. Attacks occur when the input is not properly sanitized or escaped, allowing an authenticated contributor or higher to inject arbitrary JavaScript. The injected script executes whenever a user accesses a page containing the compromised widget, potentially enabling defacement, data theft, or session hijacking.
Affected Systems
WordPress sites running aThemes Addons for Elementor version 1.1.8 or earlier are affected. Vulnerability is present in the Posts Timeline widget and in the Posts Carousel widget in its default, Banner, and Modern skins.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS data is not available and the flaw is not listed in the CISA KEV catalog. The attack vector is likely limited to users who have contributor or elevated roles, but any site visitor to a page that includes the injected widget can be impacted. Exploitation requires an authenticated user to modify the widget setting, after which the stored payload is served to all users who view the edited page.
OpenCVE Enrichment