GHSA-wfj4-gg7v-ph8qMediumCVSS 5.3

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized...

Published
May 20, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates.

🔗 References (4)