Impact
The Xpro Addons plugin for WordPress enables the injection of malicious scripts through the Pricing Widget’s onClick event setting. When a contributor or higher-level user stores a script in this field, the script is rendered and executed on any page where the widget appears, giving the attacker the ability to execute arbitrary code in visitors’ browsers. This type of stored cross‑site scripting can lead to defacement, credential theft, session hijacking or redirection to malicious sites, affecting the confidentiality, integrity and availability of the site and its users.
Affected Systems
WordPress sites that have the Xpro Addons — 140+ Widgets for Elementor plugin installed, specifically versions up to and including 1.4.20. No other products or versions are listed as affected by this vulnerability.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating a moderate to high severity. It requires authenticated access with at least contributor privileges, and the attack vector is inferred to be local via the website’s editor interface. No EPSS data is available, and the vulnerability is not cataloged in CISA’s KEV list, suggesting that while exploitability is confirmed, widespread exploitation has not been observed yet.
OpenCVE Enrichment