Stored Cross-Site Scripting in Xpro Addons for Elementor Plugin by WordPress
CVE-2026-2949
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 April 2026
What is CVE-2026-2949?
The Xpro Addons β 140+ Widgets for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitation and output escaping in the Icon Box widget. This vulnerability can be exploited by authenticated attackers with contributor-level access to inject harmful web scripts into pages. These scripts will execute whenever a user accesses the compromised page, potentially endangering user data and site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Xpro Addons β 140+ Widgets for Elementor 0 <= 1.4.24