CVE · Critical

CVE-2025-69312 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-69312 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.20 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 1.4.20 1.4.20 2026-01-19

CVE-2025-69312

The Xpro Addons plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to bypass normal file upload restrictions in versions up to 1.4.19.1. This vulnerability enables attackers to upload malicious files, potentially leading to unauthorized server access and code execution. Affected sites may be compromised by authenticated users with Author-level or higher privileges.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.