CVE-2025-7046 Overview
CVE-2025-7046 is a Stored Cross-Site Scripting (XSS) vulnerability in the Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress. The flaw affects all plugin versions up to and including 3.2.0. Authenticated attackers with Contributor-level access or higher can inject arbitrary JavaScript through the Custom JS Attributes field of the plugin's widgets. The injected scripts execute in the browser of any user who visits an affected page. The vendor, pwrplugins, partially addressed the issue in version 3.2.0 and delivered a complete fix in version 3.2.1.
Critical Impact
Authenticated contributors can inject persistent JavaScript that executes in visitors' and administrators' browsers, enabling session theft, defacement, and pivoting to higher-privileged accounts.
Affected Products
- PowerFolio (Portfolio for Elementor & Image Gallery) versions ≤ 3.2.0
- WordPress installations using the portfolio-elementor plugin
- Sites allowing Contributor-level or higher user registration
Discovery Timeline
- 2025-07-04 - CVE-2025-7046 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7046
Vulnerability Analysis
The vulnerability is a stored Cross-Site Scripting flaw classified under [CWE-79]. It resides in the widget rendering logic of two components: the Image Gallery Widget and the Portfolio Widget. Both widgets expose a Custom JS Attributes field that the plugin renders into the page markup without sufficient sanitization or output escaping.
Because the payload persists in the WordPress database, every visitor to the affected page triggers script execution. The attack requires authentication at the Contributor level, which is a low barrier on sites that permit open registration or that host multiple content contributors. Successful exploitation can lead to administrator session hijacking, forced administrative actions via CSRF chaining, and delivery of malware to site visitors.
Root Cause
The plugin accepts free-form input in the Custom JS Attributes parameter and writes it into rendered HTML attributes without escaping quotes, angle brackets, or JavaScript event handlers. The affected code paths are documented in the WordPress Trac browser at Image Gallery Widget line 492 and Portfolio Widget line 541. The partial fix in 3.2.0 addressed one code path, and version 3.2.1 completed sanitization coverage across both widgets.
Attack Vector
An attacker with Contributor privileges creates or edits a post that includes an Elementor page built with the PowerFolio Image Gallery or Portfolio widget. The attacker supplies a malicious payload in the Custom JS Attributes property, typically breaking out of the attribute context to introduce an event handler or <script> element. When an administrator previews the pending post or a public visitor loads the published page, the browser executes the payload in the site's origin. The full remediation details are available in the WordPress Changeset 3318503 and the Wordfence Vulnerability Report.
No verified proof-of-concept code has been published. The vulnerability follows the standard pattern of stored XSS in a plugin attribute field.
Detection Methods for CVE-2025-7046
Indicators of Compromise
- Post or page meta entries containing <script>, onerror=, onload=, or javascript: strings inside PowerFolio widget configuration
- Unexpected outbound requests from visitor browsers to attacker-controlled domains after loading portfolio pages
- New administrator accounts, plugin installations, or theme edits following Contributor account activity
- WordPress audit logs showing widget edits by low-privilege users on Elementor pages
Detection Strategies
- Query the wp_postmeta table for _elementor_data rows containing PowerFolio widget types with suspicious characters in custom_js_attributes
- Review Contributor and Author account activity for unusual page edits involving Elementor widgets
- Deploy a web application firewall rule that inspects post meta writes for script tags and event handlers
Monitoring Recommendations
- Enable WordPress audit logging to capture post revisions by non-Editor accounts
- Monitor browser console errors and Content Security Policy violation reports on portfolio pages
- Track plugin version inventory across WordPress deployments to identify hosts still running versions at or below 3.2.0
How to Mitigate CVE-2025-7046
Immediate Actions Required
- Update the PowerFolio plugin to version 3.2.1 or later on all WordPress installations
- Audit existing PowerFolio widget configurations for injected scripts and remove malicious content
- Review Contributor and Author accounts, disable unused accounts, and rotate credentials for any suspected compromise
- Force password resets for administrator accounts that may have loaded affected pages
Patch Information
The vendor released a partial fix in version 3.2.0 and a complete fix in version 3.2.1. The corrective code is published in WordPress Changeset 3318503. Administrators should verify the installed version via the WordPress plugin dashboard or by inspecting the plugin header in portfolio-elementor/portfolio-elementor.php.
Workarounds
- Restrict user registration and limit Contributor-level access to trusted individuals until the patch is applied
- Deploy a Content Security Policy that blocks inline scripts on public-facing pages to reduce payload execution
- Use a WAF to filter requests containing script tags or JavaScript event handlers targeting Elementor post meta endpoints
- Temporarily deactivate the PowerFolio plugin on sites where an immediate update is not feasible
# Update PowerFolio via WP-CLI on affected hosts
wp plugin update portfolio-elementor --version=3.2.1
wp plugin get portfolio-elementor --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
