Unauthorized Data Creation in Xpro Addons Plugin for WordPress
CVE-2026-7105

4.3MEDIUM

What is CVE-2026-7105?

The Xpro Addons plugin for WordPress is susceptible to an exploit that allows unauthorized data creation due to a lack of capability check in the get_menu_content_editor() function. This vulnerability affects all versions up to and including 1.5.1. Authenticated attackers with Subscriber-level access or higher can create arbitrary published posts of the xpro_content custom post type, including titles defined by the attacker. As a result, these posts can be publicly accessed on the front-end, which facilitates content injection, SEO spam, and pollution of the database.

Affected Version(s)

Xpro Addons β€” 140+ Widgets for Elementor 0 <= 1.5.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

normaandersonfrank
.