Pricing
Case studies
Login
Start trial
Xpro Elementor Addons
Xpro
Developer
1.4.27
Latest version
30,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
18 patched
1 Mitigation rules
WordPress Xpro Addons - 140+ Widgets for Elementor plugin <= 1.4.20 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.4.20
4 hours ago
WordPress Xpro Addons - 140+ Widgets for Elementor plugin <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget vulnerability
<= 1.4.24
5 hours ago
WordPress Xpro Addons - 140+ Widgets for Elementor plugin <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link vulnerability
<= 1.4.24
26/02/2026
Arbitrary File Upload vulnerability
<= 1.4.19.1
19/01/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget vulnerability
<= 1.4.7.1
31/12/2025
Cross Site Scripting (XSS) vulnerability
<= 1.4.19.1
06/12/2025
Cross Site Scripting (XSS) Vulnerability
<= 1.4.17
27/08/2025
Cross Site Scripting (XSS) vulnerability
<= 1.4.10
04/04/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.4.6.7
08/03/2025
Authenticated (Contributor+) Post Disclosure via Post Duplication vulnerability
<= 1.4.6.2
07/01/2025
Cross Site Scripting (XSS) vulnerability
<= 1.4.6.5
05/12/2024
Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
<= 1.4.6
05/11/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Post Grid Widget vulnerability
<= 1.4.4.3
27/08/2024
Cross Site Scripting (XSS) vulnerability
<= 1.4.4.2
07/08/2024
Authenticated (Contributor+) PHP Object Injection vulnerability
<= 1.4.3.1
24/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets vulnerability
<= 1.4.3
15/05/2024
Cross Site Scripting (XSS) vulnerability
<= 1.4.3.1
07/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.4.2
29/03/2024