SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84146

MEDIUM · CVSS 5.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Xpro Addons plugin for WordPress prior to version 1.7.8 is vulnerable due to a lack of capability checks, enabling unauthenticated users to access sensitive information about WooCommerce products, including titles, prices, and stock details, even if those products are not publicly published. This exposure could lead to unauthorized disclosure of product information, potentially impacting business operations and customer trust. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data leakage.

CVE
CVE-2026-84146
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
WordPress

Original NVD Description

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).