Junglewise Threat Intelligence

CVE-2026-84146: Xpro Addons for Elementor unauthenticated product information disclosure

CVE-2026-84146 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Executive brief

Xpro Addons is a WordPress plugin that extends the Elementor page builder with additional widgets for WooCommerce stores. The plugin fails to verify user permissions before exposing product details, allowing anyone to retrieve prices, SKUs, descriptions, and inventory information for products that are intentionally hidden from public view (draft, pending, private, or scheduled status). This enables attackers to enumerate and access confidential product data without any account credentials.

Technical details

The vulnerability is an information disclosure (CWE-200) in the plugin's AJAX endpoint handling. The plugin's Quick View product data endpoint (load_quick_view_product_data) does not validate user capabilities or check post status before rendering WooCommerce product summaries. An unauthenticated attacker can call this AJAX action with a publicly readable nonce (embedded in page source for all visitors) and a sequential product ID to retrieve full product metadata. No user interaction or authentication is required; the nonce is automatically available to all visitors. The plugin was patched in version 1.7.8.

Affected products

  • Xpro Addons for Elementor before 1.7.8

Timeline

  • 2026-09-02: disclosed
  • 2026-09-04: patched: Fixed in version 1.7.8

References