WordPress Plugin Vulnerabilities
Xpro Addons < 1.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function
Description
The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary published posts of the `xpro_content` custom post type with attacker-controlled titles. The created posts are publicly queryable on the front-end, enabling content injection, SEO spam, and database pollution.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
normaandersonfrank
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-08-04 (about 1 month ago)
Added
2026-08-04 (about 1 month ago)
Last Updated
2026-08-05 (about 1 month ago)