CVE-2024-4471
The Xpro Addons plugin for Elementor through version 1.4.3.1 contains a PHP Object Injection vulnerability in its export_content function where untrusted data is deserialized without proper validation. Attackers with contributor-level access or higher can exploit this to inject malicious PHP objects, though the plugin itself lacks a gadget chain for direct exploitation. If other installed plugins or themes provide a suitable gadget chain, attackers could leverage this vulnerability to execute arbitrary code, steal sensitive information, or delete files on the server.
Based on public CVE data (MITRE/NVD).