Impact
The Xpro Addons plugin for Elementor does not perform a capability or post-status check before rendering a WooCommerce product summary for a supplied product ID. This allows unauthenticated visitors to retrieve sensitive information—such as title, price, SKU, description, and stock details—about products that are draft, pending, private or scheduled. The primary impact is the disclosure of confidential product data, revealing internal business information to anyone who can request the product summary. The vulnerability is an instance of improper access control that leads to information exposure.
Affected Systems
The vulnerability affects the Xpro Addons — 140+ Widgets for Elementor WordPress plugin prior to version 1.7.8. Any deployment of this plugin version through an Elementor-based WordPress site is susceptible.
Risk and Exploitability
The exploit does not require any authentication or privileged user rights, and can be performed by any visitor with network access to the site. While the EPSS score is not available and the CVSS score is not listed, the attack vector is likely web-based, making the vulnerability easily exploitable by automated scanners or malicious actors. The KEV catalog does not list this issue, but the potential for significant confidential information leakage warrants prompt attention.
OpenCVE Enrichment