CyberRota Analysis
AI-GeneratedThe Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper validation of HTML tag names in the Pricing Table widget title. This flaw allows users with Contributor-level access or higher to inject malicious JavaScript, which can execute in the context of any user viewing the page, including administrators. WordPress site administrators and developers using this plugin should prioritize patching to mitigate potential exploitation risks.
Original NVD Description
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.