CVE · Medium

CVE-2025-15369 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15369 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.1 Missing Authorization Medium 5.3 < 1.5.1 1.5.1 2026-05-19

CVE-2025-15369

The Xpro Addons plugin for WordPress has a security flaw that allows unauthorized access to its content editor feature due to inadequate permission checks in the get_content_editor function across all versions prior to and including 1.5.0, enabling malicious actors to create publicly accessible template designs without proper authentication. This vulnerability can be exploited by unauthenticated users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.