Input validation vulnerability in 140+ Widgets | Xpro Addons For Elementor – FREE 1.4.7.1

A popular plugin for WordPress called “140+ Widgets | Xpro Addons For Elementor – FREE” has a security vulnerability that allows attackers to inject harmful scripts into the website. This can happen through certain settings in the “Site Title” widget, and it affects all versions up to 1.4.6.8. This means that attackers with Contributor-level access or higher can add harmful code to pages that will run when someone visits those pages.

Detected in:

140+ Widgets | Xpro Addons For Elementor – FREE fixed vulnerable versions: >= * <= 1.4.7.1
Xpro Addons — 140+ Widgets for Elementor fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.