Stored Cross-Site Scripting Vulnerability in Xpro Addons Plugin for Elementor
CVE-2026-11614
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 June 2026
What is CVE-2026-11614?
The Xpro Addons for Elementor plugin has a vulnerability that allows authenticated users with author-level access and above to execute arbitrary web scripts. This is due to inadequate input sanitization and output escaping in the 'custom_attributes' parameter. Attackers can exploit this flaw by injecting malicious scripts that execute whenever a user visits the affected pages, potentially leading to data theft or unauthorized actions.
Affected Version(s)
Xpro Addons β 140+ Widgets for Elementor 0 <= 1.7.2