Executive brief
The Xpro Addons plugin for WordPress, which provides additional design elements for the Elementor page builder, contains a security flaw in its Icon Box widget. This vulnerability allows users with basic contributor-level access to embed malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the Icon Box widget. The flaw exists in versions up to and including 1.4.24. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into the widget's parameters. Because the input is stored and later rendered without proper neutralization, the script executes in the context of any user's browser who views the compromised page. A patch was introduced in changeset 3470049.
Affected products
- Xpro Xpro Addons — 140+ Widgets for Elementor <= 1.4.24
Timeline
- 2026-04-04: disclosed
- 2026-04-04: advisory