CVE · Medium

CVE-2025-58198 — Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58198 Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.10 Missing Authorization Medium 6.5 < 1.2.10 1.2.10 2025-08-27

CVE-2025-58198

The Xpro Theme Builder For Elementor – FREE plugin has a security flaw that allows certain users to bypass standard permissions in WordPress installations running versions of the plugin up to 1.2.9. Specifically, contributors or higher can exploit this weakness to execute an unsanctioned operation without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.