CVE-2025-6997 Overview
CVE-2025-6997 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the ThemeREX Addons plugin for WordPress. The flaw affects all versions up to and including 2.35.1.1. Authenticated attackers with Contributor-level access or higher can supply a remote Scalable Vector Graphics (SVG) file that injects arbitrary JavaScript into rendered pages. The plugin's SVG rendering routine fails to validate the URL origin, scheme, or SVG content before output. Scripts execute in the browsers of users who access the affected pages or SVG resource.
Critical Impact
Contributor-level accounts can inject persistent JavaScript via remote SVG files, enabling session hijacking, admin account takeover, and malicious redirects across WordPress sites running vulnerable ThemeREX Addons versions.
Affected Products
- ThemeREX Addons plugin for WordPress, all versions through 2.35.1.1
- WordPress sites using the plugin's shortcode-based SVG rendering
- WordPress sites using the plugin's Elementor widget integration
Discovery Timeline
- 2025-07-19 - CVE-2025-6997 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6997
Vulnerability Analysis
The vulnerability resides in the ThemeREX Addons plugin's SVG rendering logic. The plugin exposes a svg parameter through both shortcode attributes and Elementor widget settings. When rendering, the plugin passes this parameter directly to the trx_addons_get_svg_from_file() function without validating the source URL. The retrieved content is then emitted through trx_addons_show_layout() without sanitization.
An authenticated Contributor can supply an attacker-controlled remote URL pointing to an SVG file containing embedded <script> elements or event handlers. The plugin fetches the file, renders its contents inline, and the injected JavaScript executes in the context of the WordPress site's origin.
Stored XSS on a WordPress site allows attackers to steal authenticated session cookies, perform actions on behalf of administrators, redirect visitors to phishing pages, and inject cryptominers or malware droppers into public-facing content.
Root Cause
The root cause is insufficient input sanitization and output escaping. The plugin trusts the svg parameter without enforcing an allowlist of URL schemes, restricting the URL to same-origin resources, or sanitizing the retrieved SVG markup. SVG files are XML documents that can legitimately contain <script> elements and JavaScript event handlers, which is why remote SVG inclusion without content sanitization is unsafe by design.
Attack Vector
Exploitation requires an authenticated account with Contributor privileges or above. The attacker embeds a shortcode or configures an Elementor widget with the svg parameter pointing to a remote SVG hosted on infrastructure they control. When the resulting page is viewed by another user, including administrators reviewing pending posts, the malicious SVG is fetched and its embedded scripts execute in the victim's browser session.
Because user interaction is required (a victim must load the affected page), the impact is scoped to session-level compromise rather than direct server takeover. However, hijacking an administrator session on WordPress typically leads to full site control.
No verified proof-of-concept code has been published. See the Wordfence Vulnerability Report for additional technical detail.
Detection Methods for CVE-2025-6997
Indicators of Compromise
- Post or page content containing ThemeREX shortcodes with an svg attribute pointing to an external domain
- Elementor widget configurations that reference remote SVG URLs outside the site's media library
- Outbound HTTP requests from the WordPress server to unfamiliar domains during page rendering
- SVG files in the uploads directory or fetched content containing <script> tags, onload, onerror, or onclick attributes
Detection Strategies
- Audit the wp_posts table for shortcodes referencing the vulnerable SVG parameter with non-local URLs
- Review Elementor page data (_elementor_data post meta) for widget instances that load remote SVG assets
- Inspect installed plugin versions and flag any ThemeREX Addons installation at or below 2.35.1.1
- Monitor web server logs for repeated fetches of SVG files from unusual external hosts triggered by page rendering
Monitoring Recommendations
- Alert on newly created or promoted Contributor and Author accounts followed by shortcode-based content edits
- Log and review Content Security Policy (CSP) violation reports for inline script execution on WordPress pages
- Track outbound network connections from PHP worker processes to identify remote SVG retrieval
How to Mitigate CVE-2025-6997
Immediate Actions Required
- Update ThemeREX Addons to a version later than 2.35.1.1 as soon as the vendor publishes a patched release
- Restrict Contributor and Author account creation and audit existing low-privilege accounts for anomalous activity
- Review all published and pending posts for shortcodes or Elementor widgets referencing external SVG URLs
- Rotate administrator credentials and invalidate active sessions if suspicious SVG content is found
Patch Information
At the time of publication, monitor the ThemeREX Addons plugin page and the Wordfence Vulnerability Report for the fixed version. Apply the vendor update through the WordPress plugin manager once available.
Workarounds
- Temporarily deactivate the ThemeREX Addons plugin if a patched version is not yet available
- Restrict the shortcode and Elementor widget capabilities so only trusted Editor or Administrator roles can publish content using the plugin
- Deploy a web application firewall (WAF) rule that blocks requests containing the vulnerable shortcode with remote svg URL values
- Enforce a Content Security Policy that disallows inline scripts and restricts script sources to the site's own origin
# Example: disable the plugin via WP-CLI until a patch is applied
wp plugin deactivate trx_addons
# Example: search post content for suspicious remote SVG references
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%svg=\"http%'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.