
CVE-2025-13368 The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Widget's 'onClick Event' setting in all… https://www.cve.org/CVERecord?id=CVE-2025-13368
Post summary
The Xpro Addons Elementor plugin is vulnerable to stored XSS via the Pricing Widget's onClick event, but no PoC, exploit, patch, or active exploitation details are provided.

