PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-83547 Xpro Addons CVE debrief

The Xpro Addons WordPress plugin before version 1.7.4 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks due to improper escaping of widget settings within HTML attributes. The CVE record was published on 2026-09-02T15:17:45.143Z. The source confidence is limited, and defenders should verify the affected scope, review context, and potential operational impact. Additional verification is required to confirm the vulnerability's existence and affected systems. Users of the Xpro Addons WordPress plugin, especially those with Contributor-level access or higher, should review and update the plugin to prevent potential attacks.

Vendor
Xpro Addons
Product
Xpro Addons WordPress plugin
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Users of the Xpro Addons WordPress plugin, especially those with Contributor-level access or higher, should review and update the plugin to prevent potential Stored Cross-Site Scripting attacks. Additionally, operators, platform administrators, vulnerability management teams, and security teams should be aware of the vulnerability and its potential impact on their systems and networks. They should review the affected scope, assess their exposure, and plan for remediation or mitigation as needed.

Technical summary

The Xpro Addons WordPress plugin before version 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes. This allows users with the Contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The affected product is the Xpro Addons WordPress plugin, and the vulnerability is related to improper input validation and output encoding.

Defensive priority

Medium-priority defensive review recommended due to Contributor-level access requirement for exploitation.

Recommended defensive actions

  • Review and update Xpro Addons WordPress plugin to version 1.7.4 or later
  • Restrict Contributor role and above to only necessary users
  • Monitor plugin usage and user interactions for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The evidence from WPScan indicates a potential Stored Cross-Site Scripting (XSS) vulnerability in the Xpro Addons WordPress plugin before version 1.7.4. This vulnerability allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks due to improper escaping of widget settings within HTML attributes. The source confidence is limited, and defenders should verify the affected scope, review context, and potential operational impact. Additional verification is required to confirm the vulnerability's existence and affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-83547 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-83547

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-83547 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83547

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.