Unauthorized Data Creation in Xpro Addons Plugin for WordPress
CVE-2026-7105
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-7105?
The Xpro Addons plugin for WordPress is susceptible to an exploit that allows unauthorized data creation due to a lack of capability check in the get_menu_content_editor() function. This vulnerability affects all versions up to and including 1.5.1. Authenticated attackers with Subscriber-level access or higher can create arbitrary published posts of the xpro_content custom post type, including titles defined by the attacker. As a result, these posts can be publicly accessed on the front-end, which facilitates content injection, SEO spam, and pollution of the database.
Affected Version(s)
Xpro Addons β 140+ Widgets for Elementor 0 <= 1.5.1