Junglewise Threat Intelligence

CVE-2025-15369: Xpro Addons for Elementor missing authorization in get_content_editor

CVE-2025-15369 · Severity: medium · CVSS 5.3 · Published 2026-05-20

Executive brief

The Xpro Addons plugin for WordPress, which provides additional design widgets for the Elementor page builder, contains a security flaw that allows unauthorized users to modify site content. An attacker can exploit this to create and publish new templates on a website without needing to log in. This could lead to unauthorized site changes, defacement, or the insertion of malicious content.

Technical details

The vulnerability is classified as a missing authorization (CWE-862) within the get_content_editor function of the Xpro Addons plugin. Due to the lack of proper capability checks, the function is accessible to unauthenticated users via a network request. An attacker can leverage this flaw to create and publish new Xpro templates on the affected WordPress site. The issue exists in all versions up to and including 1.5.0. Security researchers recommend updating to the latest patched version to mitigate this risk.

Affected products

  • Xpro Addons Xpro Addons — 140+ Widgets for Elementor Up to, and including, 1.5.0

Timeline

  • 2026-05-20: disclosed: Initial public disclosure of the vulnerability.
  • 2026-05-20: advisory: NVD and Wordfence published advisory details.

References

Related threats