Skip to main content

CVE-2025-2573: WPBakery Service Box Plugin XSS Vulnerability

CVE-2025-2573 is a stored cross-site scripting vulnerability in the Amazing service box Addons for WPBakery Page Builder plugin that allows authenticated attackers to inject malicious scripts via SVG uploads. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-2573 Overview

CVE-2025-2573 is a Stored Cross-Site Scripting (XSS) vulnerability in the Amazing Service Box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress. The vulnerability affects all versions up to and including 2.0.0. It stems from insufficient input sanitization and output escaping in SVG file uploads. Authenticated attackers with Author-level access or higher can inject arbitrary web scripts into SVG files. Scripts execute in the browser of any user who accesses the malicious SVG. The issue is tracked under CWE-79.

Critical Impact

Authenticated attackers with Author privileges can execute arbitrary JavaScript in the context of any WordPress user accessing the uploaded SVG, enabling session theft, admin account takeover, or malicious redirects.

Affected Products

  • Amazing Service Box Addons For WPBakery Page Builder plugin for WordPress
  • All plugin versions up to and including 2.0.0
  • WordPress installations allowing Author-level or higher accounts

Discovery Timeline

  • 2025-03-26 - CVE-2025-2573 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-2573

Vulnerability Analysis

The Amazing Service Box Addons plugin permits authenticated users to upload SVG files without sanitizing embedded scripting content. SVG is an XML-based format that supports <script> tags and JavaScript event handlers such as onload and onclick. When the plugin renders or serves these files, browsers parse the embedded JavaScript and execute it in the origin of the WordPress site.

The underlying weakness maps to CWE-79: Improper Neutralization of Input During Web Page Generation. The relevant upload handlers reside in the plugin's asb_addon.php file, as documented in the WordPress Plugin Source Code.

Root Cause

The plugin lacks validation logic to strip <script> elements, event handler attributes, and external references from uploaded SVG payloads. WordPress core does not sanitize SVG content by default, so plugins that expand the accepted MIME types must implement their own sanitization. The plugin also fails to escape output when the file is later served or embedded.

Attack Vector

An attacker with an Author-level or higher account uploads a crafted SVG file containing malicious JavaScript through the plugin's media upload interface. Any authenticated user, including administrators, who navigates to the SVG's URL triggers execution of the embedded script. The scope changes from the attacker's browser to the victim's session, enabling cookie theft, forced administrative actions, or persistent backdoor injection.

The vulnerability requires network access, low attack complexity, and low privileges. No user interaction beyond viewing the SVG is required. Refer to the Wordfence Vulnerability Report for additional technical details.

Detection Methods for CVE-2025-2573

Indicators of Compromise

  • SVG files in the WordPress wp-content/uploads/ directory containing <script> tags, onload=, onerror=, or javascript: URIs.
  • Media library entries with .svg extensions uploaded by non-administrator accounts.
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after viewing media items.
  • Newly created WordPress administrator accounts or unauthorized privilege escalations.

Detection Strategies

  • Scan the uploads directory for SVG files and inspect their XML content for scripting elements or event handler attributes.
  • Audit WordPress user activity logs for SVG uploads originating from Author, Editor, or Contributor accounts.
  • Correlate web server access logs for .svg requests followed by anomalous administrative actions such as user creation or plugin installation.

Monitoring Recommendations

  • Enable WordPress audit logging plugins to record file uploads with user attribution and timestamps.
  • Monitor for new plugin installations, theme edits, or user role modifications immediately after SVG media access.
  • Alert on browser-side Content Security Policy (CSP) violations reported by the WordPress admin domain.

How to Mitigate CVE-2025-2573

Immediate Actions Required

  • Deactivate the Amazing Service Box Addons For WPBakery Page Builder plugin until a patched version is released.
  • Review and remove any untrusted SVG files uploaded by Author-level or higher accounts since installation.
  • Audit the WordPress user list and revoke unnecessary Author, Editor, or Administrator privileges.
  • Rotate credentials and force password resets for administrator accounts that may have viewed malicious SVGs.

Patch Information

At the time of NVD publication, no fixed version beyond 2.0.0 is listed. Consult the WordPress plugin developer page and the Wordfence Vulnerability Report for updated patch availability. Apply any vendor-released update immediately once published.

Workarounds

  • Disable SVG uploads site-wide by removing image/svg+xml from the allowed MIME types in WordPress.
  • Restrict Author, Editor, and Contributor roles from uploading media until the plugin is patched or replaced.
  • Deploy a web application firewall (WAF) rule to block SVG files containing <script> or on*= event handler attributes.
  • Serve user-uploaded SVGs from a sandboxed subdomain with a restrictive Content Security Policy to contain script execution.
bash
# Disable SVG uploads via a WordPress mu-plugin filter
add_filter('upload_mimes', function($mimes) {
    unset($mimes['svg']);
    unset($mimes['svgz']);
    return $mimes;
});

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.