🔐 CVE Alert

CVE-2026-84088

UNKNOWN 0.0

Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.

Vendor unknown
Product xpro addons — 140+ widgets for elementor
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown xpro addons — 140+ widgets for elementor

Be the first to know when new unknown vulnerabilities affecting unknown xpro addons — 140+ widgets for elementor are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Xpro Addons — 140+ Widgets for Elementor
0 < 1.7.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/15940aa1-ece2-417b-ab58-a6d5de9c38ae/

Credits

Dmitrii Ignatyev WPScan