CVE-2025-15369
Unauthorized Template Creation in Xpro Addons for Elementor
Publication date: 2026-05-20
Last updated on: 2026-05-20
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| xpro | addons | to 1.5.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability exists in the Xpro Addons β 140+ Widgets for Elementor plugin for WordPress, specifically in all versions up to and including 1.5.0. It is caused by a missing capability check on the get_content_editor function. This flaw allows unauthenticated attackers to modify data by creating published Xpro templates without proper authorization.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing attackers who are not logged in to your WordPress site to create published Xpro templates. This unauthorized modification can lead to potential misuse of your website's content or functionality, possibly affecting the integrity of your site.