CVE · Medium

CVE-2026-11614 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11614 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.7.3 1.7.3 2026-06-23

CVE-2026-11614

The Xpro Addons plugin for WordPress contains a security flaw in versions up to 1.7.2, allowing malicious users with elevated permissions to introduce unauthorized code into the site's content through a specific parameter called 'custom_attributes'. This vulnerability enables attackers to embed executable scripts within pages that will be triggered when visited by other users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.