Impact
The vulnerability permits unauthenticated attackers to inject arbitrary JavaScript into pages that render a search‑results template containing the Table of Contents widget. Because the s parameter is reflected without proper sanitization or escaping, injected scripts execute in the context of any visitor, enabling session hijacking, credential theft, or defacement. The weakness is a typical reflected XSS flaw as classified in CWE‑79, which can affect confidentiality, integrity, and availability by compromising user sessions.
Affected Systems
The issue affects the Qi Addons For Elementor WordPress plugin from vendor qodeinteractive, any release up to and including version 1.11. Users relying on this plugin in their search‑results pages or templates that include the Table of Contents widget are at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. To exploit, an attacker must craft a search query containing malicious payloads that will be reflected in the s parameter while the Table of Contents widget scans the search‑results heading. This attack path does not require authentication but relies on the widget being present in templates rendering the search‑results page, which is inferred from the description.
OpenCVE Enrichment