Impact
The Xpro Addons WordPress plugin prior to version 1.7.9 does not validate or sanitize a widget link setting before it is stored and later used in a JavaScript navigation call. As a result, users with contributor privileges or higher can inject and persist arbitrary JavaScript. When any user interacts with the affected widget, the stored script executes in the victim’s browser, potentially allowing session hijacking, defacement, or the execution of additional malicious payloads.
Affected Systems
The vulnerability affects the Xpro Addons – 140+ Widgets for Elementor plugin for WordPress. All installations that have a version earlier than 1.7.9 are susceptible, regardless of the site’s overall configuration, because the flaw resides in the widget link field of the Interactive Circle Widget.
Risk and Exploitability
Because the flaw requires an authenticated user with contributor or higher role to inject the payload, the primary attack vector is an internal user. The EPSS score is less than 1%, indicating a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, once injected, the stored XSS will run in any user’s browser that interacts with the widget, granting the attacker the ability to steal credentials, perform phishing, or carry out further attacks against the site’s visitors.
OpenCVE Enrichment