Impact
A reflected and stored Cross Site Scripting vulnerability exists in the ElementsKit Elementor addons Lite plugin for WordPress versions up to 4.0.5. The flaw allows an attacker to inject arbitrary JavaScript that is executed in the context of a victim’s browser, potentially leading to theft of cookies, session hijacking, defacement, or redirection to malicious sites. The weakness is a classic input validation failure covered by CWE-79.
Affected Systems
The vulnerability affects the Roxnor ElementsKit Elementor addons Lite plugin on WordPress installations running any version through 4.0.5 inclusive. No further version details are listed, but any site using the published vulnerable versions is susceptible until the plugin is upgraded.
Risk and Exploitability
With a CVSS score of 6.5 the issue is considered moderate severity. EPSS information is not available, and the vulnerability is not in the CISA KEV catalog, suggesting no confirmed exploit activity yet. The likely attack vector is through the WordPress administrative interface or any public-facing form that the plugin processes, where malicious script payloads can be entered by an attacker. An attacker who succeeds in injecting script would run in the victim’s browser with the privileges of the logged‑in user. The impact potential is significant due to the ability to hijack session state, steal credentials, or manipulate page content.
OpenCVE Enrichment