CVE-2026-84146

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-08 19:15


NVD link : CVE-2026-84146

Mitre link : CVE-2026-84146

CVE.ORG link : CVE-2026-84146


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor