CVE-2025-7502 Overview
CVE-2025-7502 is a Stored Cross-Site Scripting (XSS) vulnerability in the WPBakery Page Builder plugin for WordPress. The flaw affects all versions up to and including 8.5. It stems from insufficient input sanitization and output escaping on user-supplied attributes across several shortcodes. Authenticated attackers holding contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any user who visits the affected page, enabling session theft, redirection, and administrative account takeover through the WordPress admin session.
Critical Impact
Contributor-level users can persist arbitrary JavaScript in published pages, executing in visitor and administrator browsers on every page load.
Affected Products
- WPBakery Page Builder for WordPress, all versions through 8.5
- WordPress sites permitting contributor-level or higher registration
- Sites using WPBakery shortcodes in published content
Discovery Timeline
- 2025-08-06 - CVE-2025-7502 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7502
Vulnerability Analysis
The vulnerability is classified as Cross-Site Scripting [CWE-79]. WPBakery Page Builder exposes multiple shortcodes that accept user-controlled attributes. The plugin fails to sanitize these attributes on input and does not escape them on output when rendering the shortcode HTML.
An authenticated attacker with contributor privileges can craft a post or page containing a shortcode with a malicious attribute value. Because the payload is stored in the WordPress database and served to every visitor, the XSS is persistent rather than reflected.
Execution occurs in the security context of the site's origin. Any authenticated user viewing the page, including administrators reviewing pending contributor submissions, will execute the payload. This creates a viable privilege escalation path from contributor to administrator through session hijacking or forced administrative actions via the WordPress REST API.
Root Cause
The root cause is missing input validation and missing output escaping in shortcode attribute handling. WPBakery does not enforce allow-lists on attribute values and passes attacker-controlled strings directly into HTML attribute contexts or inline event handlers. Standard WordPress functions such as esc_attr() and wp_kses() are not consistently applied to shortcode output.
Attack Vector
Exploitation requires network access to the WordPress site and an authenticated account with contributor role or higher. The attacker submits a page or post containing a WPBakery shortcode with a malicious attribute payload. When an administrator previews the pending submission, or when the page is published and viewed, the injected script executes. User interaction is required because a victim must load the affected page.
The scope changes from the vulnerable component to the browser, allowing the payload to interact with any resource in the site origin including the WordPress administrative interface.
No verified proof-of-concept code is publicly available. Refer to the Wordfence Vulnerability Analysis for additional technical detail on the affected shortcodes.
Detection Methods for CVE-2025-7502
Indicators of Compromise
- Post and page records in wp_posts containing WPBakery shortcodes with attribute values holding <script>, javascript:, onerror=, onload=, or onclick= tokens
- New or modified content authored by contributor-role accounts followed by rapid administrator preview activity
- Unexpected outbound requests from administrator browsers to external domains after loading plugin-rendered pages
- Creation of new administrator accounts or role changes shortly after contributor content submissions
Detection Strategies
- Query the WordPress database for shortcode attributes containing HTML event handlers or script tags, focusing on vc_ prefixed shortcodes
- Review the WordPress audit log for contributor accounts submitting content that includes WPBakery shortcodes with unusual attribute payloads
- Deploy a web application firewall rule that flags shortcode attributes containing script or event handler patterns
Monitoring Recommendations
- Monitor administrator session activity for anomalous REST API calls, particularly wp/v2/users and role modification endpoints
- Alert on newly created or elevated administrator accounts following contributor content submissions
- Track plugin version inventory across WordPress installations to identify hosts running WPBakery Page Builder 8.5 or earlier
How to Mitigate CVE-2025-7502
Immediate Actions Required
- Update WPBakery Page Builder to a version later than 8.5 as soon as the vendor releases a patched build; consult the WPBakery Release Notes for availability
- Audit all contributor, author, and editor accounts and remove any that are inactive or unrecognized
- Review recent posts and pages authored by non-administrator accounts for suspicious shortcode content
- Rotate WordPress administrator passwords and invalidate active sessions if compromise is suspected
Patch Information
The vendor tracks fixes in the WPBakery Release Notes. Site operators should apply the first release above 8.5 that addresses shortcode attribute sanitization. Confirm the fix version in the changelog before deploying to production.
Workarounds
- Restrict content creation to trusted administrator or editor accounts until a patched version is deployed
- Deploy a web application firewall with rules that block script tags and event handler attributes inside shortcode parameters
- Disable user registration and revoke contributor privileges where feasible
- Apply a Content Security Policy that restricts inline script execution to reduce impact of stored XSS payloads
# Example: enforce a restrictive CSP header via .htaccess to limit inline script execution
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.