Unrated severityNVD Advisory· Published Sep 16, 2026
CVE-2026-84088
CVE-2026-84088
Description
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.7.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.