Impact
The vulnerability is a contributor‐level Cross Site Scripting flaw that allows an attacker to inject malicious scripts into the output of the WordPress Premium Addons for Elementor plugin. An exploited XSS can compromise user accounts, steal session cookies, deface content, or serve additional malicious payloads. The flaw specifically affects all plugin releases up to and including 4.11.105 and is tied to improper sanitization of user input as identified by CWE‑79.
Affected Systems
Any WordPress site running the Leap13 Premium Addons for Elementor plugin version 4.11.105 or earlier is affected. The issue was addressed in the subsequent 4.11.106 release; users of earlier versions should upgrade to 4.11.106 or later to eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk. EPSS data is not available, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via web forms or content fields within the plugin, where a contributor can submit malicious input that is rendered unsanitized. Exploitation requires access to content submission or the plugin’s administrative interfaces, making it a plausible threat for sites that allow external contributors or have weak access controls.
OpenCVE Enrichment