The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 15:17
Updated : 2026-09-03 17:50
NVD link : CVE-2026-83547
Mitre link : CVE-2026-83547
CVE.ORG link : CVE-2026-83547
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
