N/A
2026-04-03< 1.4.25
Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget
Minimum safe version
1.4.25
Update to 1.4.25 or later to address 18 fixable vulnerabilities
Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget
CVE-2025-13368
CVE-2025-14149
CVE-2025-69312
CVE-2025-63044
CVE-2025-58195
CVE-2025-32163
140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget
CVE-2024-13649
CVE-2024-12584
CVE-2024-54253
CVE-2024-10319
CVE-2024-7791
CVE-2024-43150
WordPress Xpro Elementor Addons Plugin <= 1.4.3.1 is vulnerable to PHP Object Injection
WordPress Xpro Elementor Addons Plugin <= 1.4.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-34570
CVE-2024-2250