The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 3,511 live websites that are affected by CVE-2026-11614.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,511 live websites (89% of Xpro Elementor Addons install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 66 versions ( 99% of all versions) |
| 916 websites | |
| 243 websites | |
| 215 websites | |
| 172 websites | |
| 138 websites | |
| 118 websites | |
| 114 websites | |
| 110 websites | |
| 103 websites | |
| 101 websites |
| .com | 1,518 websites |
| .org | 168 websites |
| .de | 124 websites |
| .co.uk | 102 websites |
| .com.br | 98 websites |
| .pl | 87 websites |
| .net | 74 websites |
| .it | 73 websites |
| .ru | 61 websites |
| .com.au | 58 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.org | **,*** | ||
| *************.com | ***,*** | ||
| *****.***.ec | ***,*** | ||
| **********.at | ***,*** | ||
| ********************.***.mx | ***,*** | ||
| ***********.com | ***,*** | ||
| ********.**.uk | ***,*** | ||
| ******************.**.uk | ***,*** | ||
| *********.org | ***,*** | ||
| **************.com | ***,*** |
FAQ