
CVE-2026-2949 The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up to, and including,… https://www.cve.org/CVERecord?id=CVE-2026-2949
Post summary
The Elementor Xpro Addons plugin is vulnerable to stored XSS in the Icon Box widget, as detailed in the CVE record.


