CVE-2026-84088 UNKNOWN

CVE-2026-84088

Published: 2026-09-16

Description

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who interacts with the affected widget.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…