CVE · High

CVE-2024-4471 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4471 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.3.2 Deserialization of Untrusted Data High 8.0 < 1.4.3.2 1.4.3.2 2024-05-22

CVE-2024-4471

The Xpro Addons plugin for Elementor through version 1.4.3.1 contains a PHP Object Injection vulnerability in its export_content function where untrusted data is deserialized without proper validation. Attackers with contributor-level access or higher can exploit this to inject malicious PHP objects, though the plugin itself lacks a gadget chain for direct exploitation. If other installed plugins or themes provide a suitable gadget chain, attackers could leverage this vulnerability to execute arbitrary code, steal sensitive information, or delete files on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.