Xpro Addons — 140+ Widgets for Elementor

Information

Software Type Plugin
Software Slug xpro-elementor-addons (view on wordpress.org)
Software Status Active
Software Author xpro
Software Website elementor.wpxpro.com
Software Downloads 658,865
Software Active Installs 30,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 21 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets Patched CVE-2026-11614 6.4 Huazu Jiang (anjhz0318) June 23, 2026
Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to Unauthenticated Xpro Template Creation Patched CVE-2025-15369 5.3 at1as May 19, 2026
Xpro Addons — 140+ Widgets for Elementor <= 1.4.20 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-13368 6.4 Webbernaut April 3, 2026
Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget Patched CVE-2026-2949 6.4 Athiwat Tiprasaharn (Jitlada) April 3, 2026
Xpro Elementor Addons <= 1.5.1 - Authenticated (Contributor+) SQL Injection Patched CVE-2026-45214 6.5 daroo March 30, 2026
Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link Patched CVE-2025-14149 6.4 zer0gh0st February 26, 2026
Xpro Elementor Addons <= 1.4.19.1 - Authenticated (Author+) Arbitrary File Upload Patched CVE-2025-69312 8.8 Mdr January 19, 2026
Xpro Elementor Addons <= 1.4.19.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-63044 6.4 Abu Hurayra (HurayraIIT) December 6, 2025
Xpro Elementor Addons <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-58195 6.4 Abu Hurayra (HurayraIIT) August 27, 2025
Xpro Elementor Addons <= 1.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-32163 6.4 Prissy April 4, 2025
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget Patched CVE-2025-2108 6.4 Prissy March 19, 2025
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2024-13649 6.4 zer0gh0st March 7, 2025
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication Patched CVE-2024-12584 4.3 Webbernaut January 7, 2025
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2024-54253 6.4 João Pedro Soares de Alcântara December 5, 2024
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template Patched CVE-2024-10319 4.3 Ankit Patel November 4, 2024
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Grid Widget Patched CVE-2024-7791 6.4 RandomRoot, Bruno Vilela August 26, 2024
Xpro Elementor Addons <= 1.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2024-43150 6.4 Khalid August 7, 2024
140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection Patched CVE-2024-4471 8.0 Francesco Carlucci May 22, 2024
140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets Patched CVE-2024-4440 6.4 stealthcopter May 13, 2024
140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3 - Authenticated (Admin+) Cross Site Scripting Patched CVE-2024-34570 4.4 Manab Jyoti Dowarah May 7, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation