Skip to main content

CVE-2025-6252: Qi Addons For Elementor XSS Vulnerability

CVE-2025-6252 is a stored cross-site scripting vulnerability in Qi Addons For Elementor that allows authenticated attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-6252 Overview

The Qi Addons For Elementor plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 1.9.1. The flaw stems from insufficient input sanitization and output escaping across several parameters. Authenticated attackers with Contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any user who accesses the affected page, including administrators. The vulnerability is tracked as CWE-79 and was published to the National Vulnerability Database (NVD) on June 28, 2025.

Critical Impact

Contributor-level users can persist JavaScript payloads in WordPress pages, enabling session theft, administrative action forgery, and site defacement when higher-privileged users view the injected content.

Affected Products

  • Qodeinteractive Qi Addons For Elementor (WordPress plugin)
  • All versions up to and including 1.9.1
  • WordPress sites running the plugin with Contributor-or-above accounts enabled

Discovery Timeline

  • 2025-06-28 - CVE-2025-6252 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6252

Vulnerability Analysis

The vulnerability is a Stored Cross-Site Scripting flaw in the Qi Addons For Elementor plugin, a widget library for the Elementor page builder. Multiple widget parameters accept attacker-controlled input that is not properly sanitized on save and not properly escaped on render. When a Contributor or higher-privileged user edits a page and supplies crafted values, the payload is written to the WordPress database. On subsequent page views, the plugin outputs the values into the DOM without adequate escaping, allowing embedded JavaScript to execute in the visitor's browser context.

Because the payload is stored and rendered to every visitor of the affected page, an attacker with a low-privilege editorial role can pivot toward higher-privileged accounts. Common outcomes include session hijacking through cookie theft, forced administrative actions using nonces available in the DOM, and redirection to attacker-controlled infrastructure.

Root Cause

The root cause is missing input sanitization and missing output escaping in several parameters processed by the plugin's widgets. WordPress provides functions such as sanitize_text_field(), wp_kses_post(), and esc_attr() for these purposes, but the vulnerable code paths do not consistently apply them. The changeset diff between revisions 3308494 and 3318746 in the WordPress plugin repository shows the escaping fixes applied by the vendor.

Attack Vector

Exploitation requires an authenticated account with Contributor-level access or above and user interaction from a victim viewing the injected page. An attacker creates or edits a page using an affected Qi Addons widget and supplies a JavaScript payload in one of the vulnerable parameters. The payload persists in the database. When any user — including an administrator previewing or reviewing content — loads the page, the script executes in that user's session. See the Wordfence Vulnerability Report for additional context.

No verified public proof-of-concept code is available. Refer to the plugin main.js source and the vendor changeset for the affected code paths.

Detection Methods for CVE-2025-6252

Indicators of Compromise

  • Unexpected <script> tags, onerror, onload, or javascript: handlers in Elementor widget content stored in the wp_postmeta table
  • New or modified pages authored by Contributor-level accounts that include Qi Addons widgets
  • Outbound requests from administrator browsers to unfamiliar domains shortly after previewing user-submitted content

Detection Strategies

  • Query the WordPress database for post meta entries containing script tags or event handlers within Qi Addons widget shortcodes
  • Review the WordPress audit log for page edits by low-privileged users that add or modify Elementor widgets
  • Deploy a Web Application Firewall (WAF) ruleset covering stored XSS patterns against WordPress admin-ajax and post save endpoints

Monitoring Recommendations

  • Alert on new content submissions from Contributor accounts that contain HTML event handlers or <script> fragments
  • Monitor administrator browser sessions for anomalous XHR or fetch() calls to WordPress REST endpoints such as /wp-json/wp/v2/users
  • Track plugin version inventory across WordPress deployments and flag any instance running 1.9.1 or earlier

How to Mitigate CVE-2025-6252

Immediate Actions Required

  • Update Qi Addons For Elementor to the patched release published after changeset 3318746
  • Audit existing pages and posts for stored XSS payloads inserted by Contributor-level accounts
  • Review and, where appropriate, restrict the ability of untrusted users to hold Contributor or higher roles

Patch Information

The vendor addressed the vulnerability by adding sanitization and output escaping across the affected parameters. The fix is included in the plugin update corresponding to WordPress.org changeset 3318746. Site administrators should update through the WordPress plugin dashboard or by replacing the plugin files with the latest release.

Workarounds

  • Temporarily deactivate the Qi Addons For Elementor plugin until the update is applied
  • Restrict Contributor and Author roles to trusted users only, and require administrative review before publishing
  • Deploy a WAF rule that blocks script tags and JavaScript event handlers in requests to wp-admin/admin-ajax.php and Elementor save endpoints
bash
# Update the plugin via WP-CLI
wp plugin update qi-addons-for-elementor

# Verify the installed version is above 1.9.1
wp plugin get qi-addons-for-elementor --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.