MEDIUM
CVE-2026-84088
CVSS
6.8
Description
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.4%
Probability of exploitation in next 30 days
33.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.