Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

xpro — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting xpro. AI-powered Chinese analysis, POCs, and references for each vulnerability.

xpro operates as a specialized software solution, primarily utilized for enterprise workflow automation and data integration. Security audits reveal a concerning history of twenty-two recorded Common Vulnerabilities and Exposures, indicating persistent weaknesses in its development lifecycle. The most prevalent vulnerability classes include remote code execution and cross-site scripting, which allow attackers to compromise system integrity or steal sensitive user data. Additionally, instances of privilege escalation have been documented, enabling unauthorized users to gain administrative access. These flaws suggest inadequate input validation and insufficient access control mechanisms within the application architecture. While no single catastrophic incident has dominated public discourse, the cumulative effect of these vulnerabilities poses significant risk to organizations relying on the platform. Continuous patching and rigorous security testing are essential to mitigate these ongoing threats and ensure the stability of dependent business processes.

CVE ID Title CVSS Severity Published
CVE-2026-7105 Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function — Xpro Addons — 140+ Widgets for Elementor CWE-862 4.3 Medium 2026-08-05
CVE-2026-11614 Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2026-06-24
CVE-2025-15369 Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to Unauthenticated Xpro Template Creation — Xpro Addons — 140+ Widgets for Elementor CWE-862 5.3 Medium 2026-05-20
CVE-2026-45214 WordPress Xpro Elementor Addons plugin <= 1.5.1 - SQL Injection vulnerability — Xpro Elementor Addons CWE-89 8.5 High 2026-05-12
CVE-2025-13368 Xpro Addons — 140+ Widgets for Elementor <= 1.4.20 - Authenticated (Contributor+) Stored Cross-Site Scripting — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2026-04-04
CVE-2026-2949 Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2026-04-04
CVE-2026-32395 WordPress Xpro Addons For Beaver Builder – Lite plugin <= 1.5.6 - Broken Access Control vulnerability — Xpro Addons For Beaver Builder – Lite CWE-862 5.3 Medium 2026-03-13
CVE-2025-14149 Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2026-02-27
CVE-2025-69312 WordPress Xpro Elementor Addons plugin <= 1.4.19.1 - Arbitrary File Upload vulnerability — Xpro Elementor Addons CWE-434 9.1 Critical 2026-01-22
CVE-2025-63044 WordPress Xpro Elementor Addons plugin <= 1.4.19.1 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons CWE-79 6.5 Medium 2025-12-09
CVE-2025-58198 WordPress Xpro Theme Builder Plugin <= 1.2.9 - Broken Access Control Vulnerability — Xpro Theme Builder CWE-862 6.5 Medium 2025-08-27
CVE-2025-58195 WordPress Xpro Elementor Addons Plugin <= 1.4.17 - Cross Site Scripting (XSS) Vulnerability — Xpro Elementor Addons CWE-79 6.5 Medium 2025-08-27
CVE-2025-48232 WordPress Xpro Addons For Beaver Builder – Lite plugin <= 1.5.5 - Cross Site Scripting (XSS) Vulnerability — Xpro Addons For Beaver Builder – Lite CWE-79 6.5 Medium 2025-05-19
CVE-2025-32201 WordPress Xpro Theme Builder Plugin <= 1.2.8.4 - Broken Access Control vulnerability — Xpro Theme Builder CWE-862 4.3 Medium 2025-04-04
CVE-2025-32163 WordPress Xpro Elementor Addons plugin <= 1.4.10 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons CWE-79 6.5 Medium 2025-04-04
CVE-2025-2108 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2025-03-20
CVE-2024-13649 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2025-03-08
CVE-2024-12584 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication — Xpro Addons — 140+ Widgets for Elementor CWE-200 4.3 Medium 2025-01-08
CVE-2024-54253 WordPress Xpro Addons For Elementor plugin <= 1.4.6.5 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons CWE-79 6.5 Medium 2024-12-09
CVE-2024-10319 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template — Xpro Addons — 140+ Widgets for Elementor CWE-200 4.3 Medium 2024-11-05
CVE-2024-7791 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Grid Widget — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2024-08-27
CVE-2024-43150 WordPress Xpro Elementor Addons plugin <= 1.4.4.2 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons CWE-79 6.5 Medium 2024-08-12
CVE-2024-4471 140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection — Xpro Addons — 140+ Widgets for Elementor CWE-502 8.0 High 2024-05-23
CVE-2024-4440 140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2024-05-14
CVE-2024-34570 WordPress Xpro Elementor Addons plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons CWE-79 5.9 Medium 2024-05-08
CVE-2024-2250 130+ Widgets | Best Addons For Elementor – FREE <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting — Xpro Addons — 140+ Widgets for Elementor CWE-79 6.4 Medium 2024-03-29

This page lists every published CVE security advisory associated with xpro. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.