Executive brief
The Xpro Elementor Addons - Pro plugin for WordPress, which provides enhanced design widgets for website building, contains a security flaw in its Draw SVG widget. This vulnerability allows users with basic contributor-level access to read sensitive files stored on the web server. An attacker could use this to gain access to configuration files, passwords, or other private data, potentially leading to a full site takeover.
Technical details
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to arbitrary file reading due to insufficient input validation and path sanitization within the Draw SVG widget. Authenticated attackers with Contributor-level permissions or higher can exploit this flaw to retrieve the contents of arbitrary files on the server. The vulnerability exists in all versions up to and including 1.4.7. By manipulating the file path parameters associated with the SVG rendering component, an attacker can bypass intended directory restrictions to access sensitive system or configuration files (such as wp-config.php).
Affected products
- Xpro Elementor Addons Xpro Elementor Addons - Pro Up to, and including, 1.4.7
Timeline
- 2026-05-27: advisory: NVD publication date