Junglewise Threat Intelligence

CVE-2025-13368: Xpro Addons for Elementor Stored XSS in Pricing Widget

CVE-2025-13368 · Severity: medium · CVSS 6.4 · Published 2026-04-04

Executive brief

The Xpro Addons plugin for WordPress, which provides additional design elements for the Elementor page builder, contains a security flaw in its Pricing Widget. This vulnerability allows users with basic contributor-level access to embed malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The Xpro Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'onClick Event' setting within the Pricing Widget. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page. Because the input is stored in the database and rendered without proper security filtering, the script executes in the context of any user's browser who visits the affected page. This can lead to session hijacking or unauthorized administrative actions. The issue is addressed in versions following 1.4.20.

Affected products

  • Xpro Xpro Addons — 140+ Widgets for Elementor <= 1.4.20

Timeline

  • 2026-04-04: disclosed
  • 2026-04-04: advisory

References