Skip to main content

CVE-2025-6244: Essential Addons for Elementor XSS Vulnerability

CVE-2025-6244 is a stored XSS vulnerability in Essential Addons for Elementor affecting Calendar and Business Reviews widgets. Attackers with contributor access can inject malicious scripts. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-6244 Overview

CVE-2025-6244 is a Stored Cross-Site Scripting (XSS) vulnerability in the Essential Addons for Elementor plugin for WordPress. The flaw affects the Calendar and Business Reviews widget attributes in all versions up to and including 6.1.19. Insufficient input sanitization and output escaping allow authenticated users with Contributor-level access or above to inject arbitrary JavaScript into pages. The injected scripts execute in the browser context of any user who visits an affected page. The issue is tracked under CWE-79 and was published to NVD on July 8, 2025.

Critical Impact

Authenticated contributors can persist JavaScript payloads that execute against site visitors and administrators, enabling session theft, forced administrative actions, and site defacement.

Affected Products

  • Essential Addons for Elementor (Lite) versions up to and including 6.1.19
  • WordPress sites running the vulnerable plugin with Contributor-level accounts or higher
  • Sites using the Calendar or Business Reviews widgets exposed to public visitors

Discovery Timeline

  • 2025-07-08 - CVE-2025-6244 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6244

Vulnerability Analysis

The vulnerability resides in how the Essential Addons for Elementor plugin processes attribute values passed to the Calendar and Business Reviews widgets. The plugin accepts widget attribute input from authenticated editors but fails to apply proper sanitization on input and escaping on output. As a result, script content embedded in widget attributes is rendered as executable HTML when the page loads. Because the payload is persisted in the WordPress database, every subsequent visitor triggers the malicious script. The scope change reflects that the exploited widget can influence content beyond the injecting user's own context, targeting administrators and unauthenticated visitors. User interaction is required, since a victim must load a page containing the injected widget.

Root Cause

The root cause is missing sanitization on widget attribute inputs and missing output escaping when those attributes are rendered into page markup. WordPress provides helpers such as wp_kses_post, esc_attr, and esc_html for this purpose, but the affected widget code paths did not apply them to the vulnerable parameters. Classified under CWE-79, the flaw is a classic failure to treat editor-supplied data as untrusted before echoing it back into HTML.

Attack Vector

An attacker needs an authenticated account at Contributor level or higher on the target WordPress site. The attacker edits or creates content that includes the Calendar or Business Reviews widget and supplies a JavaScript payload in a vulnerable attribute. Once the page is saved and viewed, the payload executes in the visitor's browser. Common outcomes include session cookie theft, forced privilege escalation through administrator-triggered requests, redirection to attacker infrastructure, and injection of SEO spam or cryptominers. Public exploit code has not been published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

No verified public proof-of-concept is available. Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2025-6244

Indicators of Compromise

  • Unexpected <script> tags, event handlers such as onerror= or onload=, or javascript: URIs stored in the wp_postmeta or wp_posts tables for Elementor pages using Calendar or Business Reviews widgets.
  • Outbound requests from visitor browsers to unfamiliar domains immediately after loading pages that embed these widgets.
  • New or modified administrator accounts created shortly after contributor-authored pages containing these widgets were published.

Detection Strategies

  • Audit Elementor page content for the strings eael-calendar and eael-business-reviews and inspect stored widget attributes for HTML or script content.
  • Review WordPress user activity logs for contributor or author accounts that submitted or edited pages using the affected widgets in the vulnerable version window.
  • Correlate web server logs with authenticated editor sessions to identify anomalous saves against the Elementor REST endpoints used by the plugin.

Monitoring Recommendations

  • Monitor the installed plugin version and alert when Essential Addons for Elementor reports a version at or below 6.1.19.
  • Deploy a Content Security Policy (CSP) in report-only mode to surface unexpected inline script execution on public pages.
  • Track newly created or elevated WordPress accounts and unusual role changes that follow contributor content submissions.

How to Mitigate CVE-2025-6244

Immediate Actions Required

  • Update Essential Addons for Elementor to the version published in WordPress changeset 3318211, which is the first release above 6.1.19.
  • Audit all pages that use the Calendar and Business Reviews widgets and remove any suspicious attribute content prior to re-publishing.
  • Rotate credentials for all administrator accounts and invalidate active sessions if injected script content is confirmed.

Patch Information

The vendor addressed the vulnerability in the plugin update tracked in WordPress changeset 3318211. The fix adds proper sanitization on input and escaping on output for the vulnerable Calendar and Business Reviews widget attributes. Site owners should apply the update through the WordPress plugin dashboard or via wp plugin update essential-addons-for-elementor.

Workarounds

  • Restrict Contributor and Author role assignments and require administrator review before publishing pages that include third-party Elementor widgets.
  • Disable the Calendar and Business Reviews widgets from the Essential Addons settings panel until the patched version is deployed.
  • Enforce a strict CSP that blocks inline script execution to reduce the impact of stored XSS payloads.
bash
# Update the plugin using WP-CLI
wp plugin update essential-addons-for-elementor
wp plugin get essential-addons-for-elementor --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.