PatchSiren cyber security CVE debrief
CVE-2026-83547 Xpro Addons CVE debrief
The Xpro Addons WordPress plugin before version 1.7.4 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks due to improper escaping of widget settings within HTML attributes. The CVE record was published on 2026-09-02T15:17:45.143Z. The source confidence is limited, and defenders should verify the affected scope, review context, and potential operational impact. Additional verification is required to confirm the vulnerability's existence and affected systems. Users of the Xpro Addons WordPress plugin, especially those with Contributor-level access or higher, should review and update the plugin to prevent potential attacks.
- Vendor
- Xpro Addons
- Product
- Xpro Addons WordPress plugin
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Users of the Xpro Addons WordPress plugin, especially those with Contributor-level access or higher, should review and update the plugin to prevent potential Stored Cross-Site Scripting attacks. Additionally, operators, platform administrators, vulnerability management teams, and security teams should be aware of the vulnerability and its potential impact on their systems and networks. They should review the affected scope, assess their exposure, and plan for remediation or mitigation as needed.
Technical summary
The Xpro Addons WordPress plugin before version 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes. This allows users with the Contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The affected product is the Xpro Addons WordPress plugin, and the vulnerability is related to improper input validation and output encoding.
Defensive priority
Medium-priority defensive review recommended due to Contributor-level access requirement for exploitation.
Recommended defensive actions
- Review and update Xpro Addons WordPress plugin to version 1.7.4 or later
- Restrict Contributor role and above to only necessary users
- Monitor plugin usage and user interactions for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The evidence from WPScan indicates a potential Stored Cross-Site Scripting (XSS) vulnerability in the Xpro Addons WordPress plugin before version 1.7.4. This vulnerability allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks due to improper escaping of widget settings within HTML attributes. The source confidence is limited, and defenders should verify the affected scope, review context, and potential operational impact. Additional verification is required to confirm the vulnerability's existence and affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83547 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83547
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83547 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83547
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/a8298cc0-9e5b-41e2-ba44-b6f1bad30a67/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.