MEDIUM

CVE-2026-84088

2026-09-16 CVSS v3.1
CVSS
6.8

Description

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.4%
Probability of exploitation in next 30 days
33.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE