CVE
CVE-2026-2949 — Xpro Addons — 140+ Widgets for Elementor < 1.4.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-2949 | Xpro Addons — 140+ Widgets for Elementor < 1.4.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget | — | Unknown | < 1.4.25 | 1.4.25 | — | — |
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.