Unrated severityNVD Advisory· Published Sep 4, 2026
Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View
CVE-2026-84146
Description
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.7.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/8e7cdd07-0337-4e0b-adf6-b865e13322a2/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.