Junglewise Threat Intelligence

CVE-2026-83547: Xpro Addons stored XSS in widget settings

CVE-2026-83547 · Severity: medium · CVSS 6.8 · Published 2026-09-02

Executive brief

Xpro Addons is a popular WordPress plugin that extends the Elementor page builder with additional widgets. The plugin fails to properly escape widget configuration settings before displaying them in HTML, allowing authenticated users with Contributor role or higher to inject malicious JavaScript code. This stored attack affects anyone who views pages containing the compromised widgets, potentially leading to account hijacking or data theft.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in multiple widgets (Interactive Circle and Line Chart) within the Xpro Addons plugin. The root cause is inadequate output escaping of user-supplied widget settings before insertion into HTML attributes. Attack preconditions require an authenticated user with Contributor role or above; no network traversal is needed beyond normal WordPress access. An attacker can inject JavaScript payloads into widget configuration fields (e.g., item titles, dataset labels) that execute in the browsers of all users who view the affected page. The vulnerability was patched in version 1.7.4.

Affected products

  • Xpro Elementor Addons 1.6.0 to 1.7.3

Timeline

  • 2026-09-01: disclosed
  • 2026-09-02: patched: Fixed in version 1.7.4

References