CVE-2025-15369

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-20 04:16

Updated : 2026-07-24 10:10


NVD link : CVE-2025-15369

Mitre link : CVE-2025-15369

CVE.ORG link : CVE-2025-15369


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization