CVE-2026-84088
Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
| Vendor | unknown |
| Product | xpro addons — 140+ widgets for elementor |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown xpro addons — 140+ widgets for elementor
Be the first to know when new unknown vulnerabilities affecting unknown xpro addons — 140+ widgets for elementor are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Xpro Addons — 140+ Widgets for Elementor
0 < 1.7.9
References
Credits
Dmitrii Ignatyev WPScan