Skip to main content

CVE-2025-8146: Qi Addons For Elementor XSS Vulnerability

CVE-2025-8146 is a stored cross-site scripting flaw in Qi Addons For Elementor plugin for WordPress that enables authenticated attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-8146 Overview

CVE-2025-8146 is a Stored Cross-Site Scripting (XSS) vulnerability in the Qi Addons For Elementor plugin for WordPress. The flaw resides in the plugin's TypeOut Text widget and affects all versions up to and including 1.9.2. Insufficient input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary JavaScript. The injected payload executes in the browser of any user who views the affected page. The vulnerability is tracked under CWE-79.

Critical Impact

Authenticated contributors can persist arbitrary JavaScript in published pages, enabling session theft, administrative action forgery, and site defacement against visitors and privileged users.

Affected Products

  • Qi Addons For Elementor plugin for WordPress
  • All plugin versions up to and including 1.9.2
  • WordPress sites where contributor-or-higher accounts can author content using the TypeOut Text widget

Discovery Timeline

  • 2025-08-02 - CVE-2025-8146 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8146

Vulnerability Analysis

The Qi Addons For Elementor plugin extends the Elementor page builder with additional widgets, including the TypeOut Text widget. The widget accepts user-supplied attributes intended to control text content and display behavior. The plugin fails to sanitize these attributes on input and does not escape them on output when rendering the widget on the front end.

An authenticated user with the WordPress Contributor role or higher can insert crafted values that break out of the intended HTML context. The stored payload persists in the post or page metadata and executes each time a visitor loads the rendered page. Because Contributor is the minimum required role, exploitation depends only on account access that many multi-author WordPress sites grant broadly.

Root Cause

The root cause is missing input sanitization and missing output escaping on attributes handled by the TypeOut Text widget. WordPress provides functions such as wp_kses_post(), esc_attr(), and esc_html() for context-appropriate escaping, but the vulnerable widget renders attribute values into HTML without applying them. This classifies the issue as CWE-79: Improper Neutralization of Input During Web Page Generation.

Attack Vector

Exploitation requires an authenticated session with at least Contributor privileges. The attacker edits or creates a page or post, adds a TypeOut Text widget, and supplies attributes containing JavaScript, such as event handlers or <script> fragments. Once saved, the payload triggers in the browser of any user who accesses the page, including administrators previewing pending posts. See the Wordfence Vulnerability Report for additional advisory context.

No verified proof-of-concept code is published in the referenced sources. The vulnerability mechanism is described in prose only; refer to the WordPress Changeset Update for the code changes applied in the fix.

Detection Methods for CVE-2025-8146

Indicators of Compromise

  • Post or page content containing TypeOut Text widget attributes with <script> tags, on* event handlers, or javascript: URIs.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains originating from pages rendered by the plugin.
  • New or modified posts authored by Contributor-role accounts that embed Elementor TypeOut Text widgets.

Detection Strategies

  • Query the wp_posts and wp_postmeta tables for Elementor data referencing the qi_addons_for_elementor TypeOut widget and inspect attribute values for HTML or script content.
  • Run a static scan of the site using a WordPress vulnerability scanner that recognizes CVE-2025-8146.
  • Review web server access logs for administrator sessions loading pages authored by lower-privileged users shortly before suspicious activity.

Monitoring Recommendations

  • Alert on creation or modification of published content by Contributor-role accounts.
  • Monitor browser Content Security Policy (CSP) violation reports for inline script or event-handler execution on plugin-rendered pages.
  • Track plugin version inventory to identify sites still running Qi Addons For Elementor 1.9.2 or earlier.

How to Mitigate CVE-2025-8146

Immediate Actions Required

  • Update Qi Addons For Elementor to the patched version released after 1.9.2 as noted in the WordPress plugin changeset.
  • Audit all pages that use the TypeOut Text widget for existing malicious attribute values and remove any injected scripts.
  • Review Contributor and Author accounts for unexpected users, and rotate credentials where account integrity is uncertain.

Patch Information

The vendor addressed the sanitization and escaping gap in the plugin repository. See the WordPress Changeset Update for the applied fix and the Qi Addons Developer Info page for release history. Site administrators should update through the WordPress plugin manager or reinstall from the official repository.

Workarounds

  • Restrict Contributor and higher roles to trusted users until the plugin is updated.
  • Disable the TypeOut Text widget in Elementor settings if it is not required by the site.
  • Deploy a Web Application Firewall (WAF) rule that blocks script tags and event-handler attributes in Elementor widget payloads submitted through the WordPress admin.
bash
# Configuration example: locate and update the affected plugin via WP-CLI
wp plugin list --name=qi-addons-for-elementor --fields=name,version,status
wp plugin update qi-addons-for-elementor
wp plugin list --name=qi-addons-for-elementor --fields=name,version,status

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.