Description
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
Published: 2026-09-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Xpro Addons plugin for Elementor does not perform a capability or post-status check before rendering a WooCommerce product summary for a supplied product ID. This allows unauthenticated visitors to retrieve sensitive information—such as title, price, SKU, description, and stock details—about products that are draft, pending, private or scheduled. The primary impact is the disclosure of confidential product data, revealing internal business information to anyone who can request the product summary. The vulnerability is an instance of improper access control that leads to information exposure.

Affected Systems

The vulnerability affects the Xpro Addons — 140+ Widgets for Elementor WordPress plugin prior to version 1.7.8. Any deployment of this plugin version through an Elementor-based WordPress site is susceptible.

Risk and Exploitability

The exploit does not require any authentication or privileged user rights, and can be performed by any visitor with network access to the site. While the EPSS score is not available and the CVSS score is not listed, the attack vector is likely web-based, making the vulnerability easily exploitable by automated scanners or malicious actors. The KEV catalog does not list this issue, but the potential for significant confidential information leakage warrants prompt attention.

Generated by OpenCVE AI on September 4, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Xpro Addons plugin to version 1.7.8 or later, where the capability check has been added.
  • Disable or restrict the Quick View functionality for unauthenticated users to prevent unintended product summary rendering.
  • Limit WooCommerce product visibility settings or apply role-based access controls to ensure only authorized users can request product details.

Generated by OpenCVE AI on September 4, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 04 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
Title Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-04T06:00:06.679Z

Reserved: 2026-09-01T07:29:49.364Z

Link: CVE-2026-84146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T07:17:11.037

Modified: 2026-09-04T07:17:11.037

Link: CVE-2026-84146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T07:30:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control