PT-2026-68039 · WordPress · Xpro Addons
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Xpro Addons versions prior to 1.5.2
Description
The Xpro Addons plugin for WordPress contains a flaw allowing unauthorized data creation due to a missing capability check in the
get menu content editor() function. Authenticated users with Subscriber-level access or higher can create arbitrary published posts of the xpro content custom post type using titles they control. These posts are publicly accessible on the front-end, which can lead to content injection, SEO spam, and database pollution.Recommendations
Update the plugin to version 1.5.2 or later.
As a temporary workaround, restrict access to the
get menu content editor() function to prevent unauthorized users from creating content.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xpro Addons