Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Xpro Xpro xpro Addons — 140+ Widgets For Elementor |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Xpro Xpro xpro Addons — 140+ Widgets For Elementor |
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 04 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Fri, 04 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status). | |
| Title | Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-04T12:42:41.867Z
Reserved: 2026-09-01T07:29:49.364Z
Link: CVE-2026-84146
Updated: 2026-09-04T12:42:36.753Z
Status : Received
Published: 2026-09-04T07:17:11.037
Modified: 2026-09-04T13:20:10.980
Link: CVE-2026-84146
No data.
OpenCVE Enrichment
Updated: 2026-09-04T18:00:04Z