Impact
Contributor Cross Site Scripting (XSS) vulnerability allows an attacker to inject malicious script through the King Addons for Elementor plugin when accessing or inputting data. This flaw can be leveraged to execute arbitrary JavaScript in the context of a visitor's browser, potentially enabling session hijacking, credential theft, defacement, or the execution of additional malware. The impact is primarily on confidentiality and integrity of user data, and can be used to perform phishing or other social engineering attacks on site visitors.
Affected Systems
King Addons for Elementor plugin for WordPress users running version 51.1.86 or earlier are affected. This includes all installations that have not applied the latest patch upgrade.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating a medium risk. The EPSS score is not available and it is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. However, given the nature of XSS, an attacker who can supply content to the plugin could likely exploit it, especially if the plugin is exposed to user‑generated input.
OpenCVE Enrichment