Loading market data...
← Back to CVE feed

CVE-2026-84146

MEDIUM CVSS 5.3 View on NVD ↗

Description

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 04, 2026 07:17 UTC Modified: Sep 04, 2026 13:20 UTC