CVE-2026-84088: Unknown Xpro Addons — 140+ Widgets For Elementor
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
Affected products
- Unknown Xpro Addons — 140+ Widgets For Elementor: before 1.7.9 (fixed in 1.7.9)
Published 2026-09-16. Last modified 2026-09-17.