CVE · High

CVE-2026-45214 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-45214 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2 High 8.5 < 1.5.2 1.5.2 2026-03-30

CVE-2026-45214

The Xpro Elementor Addons plugin for WordPress contains a security flaw in versions 1.5.1 and earlier, which allows malicious users with elevated permissions to inject unauthorized SQL code into database queries. This vulnerability arises from inadequate protection against user-input data, enabling attackers to craft malicious SQL statements that can potentially reveal sensitive information stored within the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.