CVE-2025-7845 Overview
CVE-2025-7845 is a Stored Cross-Site Scripting (XSS) vulnerability in the Stratum – Elementor Widgets plugin for WordPress. The flaw affects all versions up to and including 1.6.0. It resides in the plugin's Advanced Google Maps and Image Hotspot widgets, which fail to properly sanitize input and escape output on user-supplied attributes. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected script executes in the browser of any user who views the affected page. The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Contributor-level attackers can persist arbitrary JavaScript in WordPress pages, enabling session theft, credential harvesting, or administrative account takeover when higher-privileged users load the page.
Affected Products
- Stratum – Elementor Widgets plugin for WordPress (all versions ≤ 1.6.0)
- Sites using the Advanced Google Maps widget from Stratum
- Sites using the Image Hotspot widget from Stratum
Discovery Timeline
- 2025-08-01 - CVE-2025-7845 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7845
Vulnerability Analysis
The Stratum – Elementor Widgets plugin renders user-controlled attributes within widget templates without sufficient sanitization or output escaping. Contributor-level users can author draft posts and pages using Elementor widgets. When they configure the Advanced Google Maps or Image Hotspot widgets, attacker-controlled values pass through to the rendered HTML. The plugin fails to apply WordPress escaping functions such as esc_attr() or esc_html() on these attributes. As a result, script payloads embedded in widget parameters persist in the database and execute on page load. See the vulnerable template in the WordPress Plugin Template File for reference.
Root Cause
The root cause is missing input sanitization and output escaping on widget attributes handled by the Advanced Google Maps and Image Hotspot components. WordPress plugin developers must escape all user-controlled data before rendering it into HTML contexts. Stratum ≤ 1.6.0 emits attribute values directly into the DOM, allowing script tags and event handlers to reach the browser unmodified.
Attack Vector
Exploitation requires an authenticated account with contributor privileges or higher. The attacker creates or edits a page using one of the vulnerable widgets and injects a JavaScript payload into an attribute field. Once the page is viewed by any visitor, including administrators, the payload executes under the site's origin. This enables cookie theft, forced actions via the WordPress REST API, or injection of persistent backdoors when an administrator triggers the payload.
No verified public proof-of-concept code has been published. See the Wordfence Vulnerability Report for additional technical details.
Detection Methods for CVE-2025-7845
Indicators of Compromise
- Unexpected <script> tags, on* event handlers, or javascript: URIs stored within Elementor page metadata for the stratum-advanced-google-map or stratum-image-hotspot widgets.
- Contributor or author accounts creating or modifying pages that contain Stratum widgets outside normal editorial patterns.
- Outbound requests from visitor browsers to unfamiliar domains after loading pages that embed the affected widgets.
Detection Strategies
- Query the WordPress wp_postmeta table for _elementor_data entries referencing Stratum widget types and inspect stored attribute values for HTML or JavaScript markup.
- Deploy a Web Application Firewall (WAF) rule that inspects POST requests to admin-ajax.php and Elementor save endpoints for script payloads targeting Stratum widget attributes.
- Review WordPress audit logs for post revisions authored by contributor-level accounts that introduce Stratum widgets.
Monitoring Recommendations
- Enable a WordPress activity log plugin to track post edits, user role changes, and plugin configuration changes.
- Monitor Content Security Policy (CSP) violation reports for inline script executions on pages hosted by the WordPress site.
- Alert on newly created contributor or author accounts, particularly on sites that accept user registration.
How to Mitigate CVE-2025-7845
Immediate Actions Required
- Update the Stratum – Elementor Widgets plugin to a version later than 1.6.0 that includes the fix from WordPress Changeset #3335410.
- Audit existing pages that use the Advanced Google Maps and Image Hotspot widgets for injected script content and remove any malicious payloads.
- Review contributor, author, and editor accounts for unauthorized users and rotate credentials for suspected accounts.
Patch Information
The plugin maintainers addressed the flaw in a version released after 1.6.0. Refer to the Stratum Plugin Developer Info page for the current release and changelog. Update through the WordPress admin dashboard under Plugins → Installed Plugins, or via WP-CLI using wp plugin update stratum.
Workarounds
- Deactivate the Stratum – Elementor Widgets plugin until it can be updated if the affected widgets are not in active use.
- Restrict contributor and author role assignments and require editorial review before publishing content that includes Stratum widgets.
- Deploy a WAF ruleset such as those provided by Wordfence to block known XSS payloads targeting the affected widget attributes.
# Update Stratum plugin via WP-CLI
wp plugin update stratum
# Verify installed version
wp plugin get stratum --field=version
# Temporary deactivation if patching is delayed
wp plugin deactivate stratum
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
