CVE-2026-84146
EUVD-2026-7091304.09.2026, 07:17
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration