Loading market data...
← Back to CVE feed

CVE-2026-83547

MEDIUM CVSS 6.8 View on NVD ↗

Description

The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Published: Sep 02, 2026 15:17 UTC Modified: Sep 02, 2026 15:17 UTC