Executive brief
Xpro Addons is a WordPress plugin that provides additional design elements for the Elementor page builder. A security flaw allows users with author-level permissions or higher to inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Xpro Addons plugin for Elementor (WordPress) contains a stored cross-site scripting (XSS) vulnerability within the 'custom_attributes' parameter. The root cause is a failure to properly sanitize user input and escape output in several widget components, including the image scroller, animated link, and author box. An authenticated attacker with author-level privileges or higher can inject arbitrary JavaScript into a page. This script executes in the context of any user's browser session when they visit the compromised page. The issue is addressed in version 1.7.3.
Affected products
- Xpro Addons Xpro Addons — 140+ Widgets for Elementor up to, and including, 1.7.2
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.7.3/inc/helper-functions.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.7.3/widgets/image-scroller/layout/frontend.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/inc/helper-functions.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/animated-link/layout/frontend.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/author-box/layout/frontend.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/button/layout/frontend.php
- https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/hero-slider/layout/frontend.php