Description
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Plugin
AI Analysis

Impact

The Xpro Addons WordPress plugin prior to version 1.7.9 does not validate or sanitize a widget link setting before it is stored and later used in a JavaScript navigation call. As a result, users with contributor privileges or higher can inject and persist arbitrary JavaScript. When any user interacts with the affected widget, the stored script executes in the victim’s browser, potentially allowing session hijacking, defacement, or the execution of additional malicious payloads.

Affected Systems

The vulnerability affects the Xpro Addons – 140+ Widgets for Elementor plugin for WordPress. All installations that have a version earlier than 1.7.9 are susceptible, regardless of the site’s overall configuration, because the flaw resides in the widget link field of the Interactive Circle Widget.

Risk and Exploitability

Because the flaw requires an authenticated user with contributor or higher role to inject the payload, the primary attack vector is an internal user. The EPSS score is less than 1%, indicating a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, once injected, the stored XSS will run in any user’s browser that interacts with the widget, granting the attacker the ability to steal credentials, perform phishing, or carry out further attacks against the site’s visitors.

Generated by OpenCVE AI on September 16, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Xpro Addons plugin to version 1.7.9 or later.
  • If an immediate update is not feasible, remove or disable the Interactive Circle Widget on all sites to prevent storage of malicious links.
  • Restrict contributor and higher role permissions so that only patch is applied.
  • Audit existing widget configurations for unexpected JavaScript and remove any suspicious entries.
  • Monitor site traffic for unusual client‑side activity indicative of XSS exploitation.

Generated by OpenCVE AI on September 16, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
Title Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-16T06:00:13.021Z

Reserved: 2026-09-01T06:31:28.441Z

Link: CVE-2026-84088

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:33.563

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-84088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')