CVE Database /
CVE-2025-15369
CVE · Medium
CVE-2025-15369 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-15369
|
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.1 |
Missing Authorization |
Medium
5.3
|
< 1.5.1
|
1.5.1 |
2026-05-19 |
—
|
CVE-2025-15369
The Xpro Addons plugin for WordPress has a security flaw that allows unauthorized access to its content editor feature due to inadequate permission checks in the get_content_editor function across all versions prior to and including 1.5.0, enabling malicious actors to create publicly accessible template designs without proper authentication. This vulnerability can be exploited by unauthenticated users.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings