Home

Description

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates.

PUBLISHED Reserved 2025-12-30 | Published 2026-05-20 | Updated 2026-05-20 | Assigner Wordfence




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Timeline

2025-12-21:Discovered
2026-01-28:Vendor Notified
2026-05-19:Disclosed

Credits

Alex Hickey finder

References

www.wordfence.com/...-de14-42bc-bf51-f9adceba0d32?source=cve

plugins.trac.wordpress.org/...entor-addons/trunk?rev=3508547

cve.org (CVE-2025-15369)

nvd.nist.gov (CVE-2025-15369)

Download JSON