MEDIUM
Xpro Addons
CVE published 2026-09-02
CVE-2026-83547
The Xpro Addons WordPress plugin before version 1.7.4 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks due to improper escaping of widget settings within HTML attributes. The CVE record was published on 2026-09-02T15:17:45.143Z. The source confidence is limited, and defenders [truncated]