Executive brief
Xpro Elementor Addons is a WordPress plugin used to add custom design elements and widgets to websites. A security flaw in this plugin allows an attacker with basic user permissions to perform a 'blind' SQL injection attack. This could allow an unauthorized person to extract sensitive information from the website's database, potentially compromising user data or site configuration.
Technical details
A Blind SQL Injection vulnerability exists in the Xpro Elementor Addons plugin for WordPress due to improper neutralization of special elements used in an SQL command. The flaw is present in versions up to and including 1.5.1. An attacker with 'Contributor' level privileges or higher can exploit this vulnerability via network requests to interact directly with the database. Successful exploitation allows the attacker to extract sensitive information through inference (blind injection). The issue is addressed in version 1.5.2.
Affected products
- Xpro Xpro Elementor Addons <= 1.5.1
Timeline
- 2026-02-28: other: Reported by researcher daroo
- 2026-03-30: advisory: Patchstack advisory published
- 2026-05-12: disclosed: CVE published to NVD