CVE · Medium

CVE-2026-7105 — Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7105 Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2 Missing Authorization Medium 4.3 < 1.5.2 1.5.2 2026-08-04

CVE-2026-7105

A security flaw in Xpro Addons for WordPress allows malicious users with Subscriber-level access or higher to create unauthorized published posts of a specific custom post type through a function lacking proper capability checks. This vulnerability affects all plugin versions up to 1.5.1, enabling attackers to inject arbitrary content and manipulate the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.