Vulnerabilities > Wpxpro > Xpro Addons FOR Elementor > 1.4.6.2

DATE CVE VULNERABILITY TITLE RISK
2025-03-08 CVE-2024-13649 Cross-site Scripting vulnerability in Wpxpro Xpro Addons for Elementor
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to insufficient input sanitization and output escaping.
network
low complexity
wpxpro CWE-79
5.4
2025-01-08 CVE-2024-12584 Information Exposure vulnerability in Wpxpro Xpro Addons for Elementor
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function.
network
low complexity
wpxpro CWE-200
6.5