CVE-2026-84146
Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
| Vendor | unknown |
| Product | xpro addons — 140+ widgets for elementor |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown xpro addons — 140+ widgets for elementor
Be the first to know when new medium vulnerabilities affecting unknown xpro addons — 140+ widgets for elementor are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Xpro Addons — 140+ Widgets for Elementor
0 < 1.7.8
References
Credits
Moshe WPScan