CVE-2026-83547

The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-83547

Mitre link : CVE-2026-83547

CVE.ORG link : CVE-2026-83547


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')