Skip to main content

CVE-2025-7646: Elementor Plus Addons XSS Vulnerability

CVE-2025-7646 is a stored XSS flaw in The Plus Addons for Elementor WordPress plugin that lets attackers inject malicious scripts. This article covers the technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-7646 Overview

CVE-2025-7646 is a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in The Plus Addons for Elementor plugin for WordPress. The flaw resides in the custom script parameter and affects all versions up to and including 6.3.10. Authenticated attackers with Contributor-level access or higher can inject arbitrary JavaScript into pages, even without the unfiltered_html capability. The injected scripts execute in the browser of any visitor who loads an affected page. The plugin ships as a popular Elementor extension providing widgets, page templates, mega menus, and WooCommerce features, expanding the attack surface across many WordPress sites.

Critical Impact

Contributor-level accounts can persist malicious JavaScript into published pages, enabling session theft, credential harvesting, and administrative takeover when higher-privileged users view the content.

Affected Products

  • The Plus Addons for Elementor (WordPress plugin) versions ≤ 6.3.10
  • Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce features bundled in the plugin
  • Fixed in version 6.3.11

Discovery Timeline

  • 2025-08-01 - CVE-2025-7646 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7646

Vulnerability Analysis

The vulnerability is a stored XSS flaw exposed through the plugin's custom script parameter within the tp_hovercard widget. WordPress normally restricts unfiltered HTML and script content to users granted the unfiltered_html capability. The affected widget bypasses that control by rendering user-supplied script content directly into the page output. Any authenticated user with Contributor privileges or higher can therefore embed arbitrary JavaScript into content they author.

Because the payload persists in the database and executes when other users, including administrators, load the page, an attacker can hijack sessions, exfiltrate authenticated API tokens, or perform actions in the context of higher-privileged accounts. The scope change reflected in the CVSS vector indicates the injected script operates outside the vulnerable component's original security context, affecting site visitors and administrators alike.

Root Cause

The root cause is missing input sanitization and output escaping in the custom script handling logic of the tp_hovercard widget. Instead of enforcing WordPress's current_user_can('unfiltered_html') check or applying wp_kses sanitization to the field, the plugin trusts input from any user permitted to edit the widget. See the plugin source at WordPress Plugin Widget File for the fixed handler.

Attack Vector

Exploitation requires an authenticated session with at least Contributor privileges. The attacker edits a page using the vulnerable widget, supplies a JavaScript payload through the custom script parameter, and saves the content. When any visitor, editor, or administrator opens the page, the browser executes the stored payload under the site's origin. Details are documented in the Wordfence Vulnerability Report.

Detection Methods for CVE-2025-7646

Indicators of Compromise

  • New or modified posts and pages authored by Contributor accounts that include <script> tags or event handlers such as onload= and onerror=.
  • Unexpected outbound requests from browsers loading site pages to attacker-controlled domains.
  • WordPress postmeta entries associated with tp_hovercard widget instances containing script payloads.

Detection Strategies

  • Audit the wp_posts and wp_postmeta tables for entries referencing tp_hovercard combined with <script, javascript:, or encoded equivalents.
  • Inspect Elementor page data for hovercard widgets whose custom script fields are non-empty and originate from non-administrative authors.
  • Review web server access logs for anomalous POST requests to admin-ajax.php or the Elementor editor endpoints from Contributor-tier accounts.

Monitoring Recommendations

  • Enable file integrity monitoring on the wp-content/plugins/the-plus-addons-for-elementor-page-builder/ directory.
  • Alert on any Contributor account that publishes or updates content containing inline scripts.
  • Deploy Content Security Policy (CSP) reporting to surface unexpected script execution originating from stored payloads.

How to Mitigate CVE-2025-7646

Immediate Actions Required

  • Upgrade The Plus Addons for Elementor to version 6.3.11 or later on every WordPress site running the plugin.
  • Review all pages containing tp_hovercard widgets for injected scripts and remove untrusted content.
  • Rotate credentials and session tokens for administrator accounts that may have loaded compromised pages.

Patch Information

The vendor addressed the vulnerability in version 6.3.11 of The Plus Addons for Elementor. The fixed handler for the custom script parameter is available in the plugin source repository at WordPress Plugin Widget File.

Workarounds

  • Temporarily restrict Contributor and Author accounts from editing pages that use the tp_hovercard widget until the plugin is updated.
  • Disable the vulnerable widget through the plugin settings if upgrading is not immediately feasible.
  • Enforce a strict Content Security Policy that blocks inline scripts to reduce the impact of stored XSS payloads.
  • Require multi-factor authentication for all WordPress accounts with content editing privileges.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.