Skip to main content

CVE-2025-8149: aThemes Addons for Elementor XSS Vulnerability

CVE-2025-8149 is a stored XSS vulnerability in the aThemes Addons for Elementor WordPress plugin affecting versions up to 1.1.2. Authenticated attackers can inject malicious scripts through the Countdown widget. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-8149 Overview

CVE-2025-8149 is a Stored Cross-Site Scripting (XSS) vulnerability in the aThemes Addons for Elementor plugin for WordPress. The flaw affects all versions up to and including 1.1.2 and resides in the plugin's Countdown widget. Insufficient input sanitization and output escaping on user-supplied attributes allow authenticated attackers with contributor-level access or above to inject arbitrary JavaScript into pages. The injected payload executes in any visitor's browser when they access the affected page, enabling session theft, forced redirects, or unauthorized administrative actions if a privileged user views the content. The vulnerability is tracked under [CWE-79].

Critical Impact

Authenticated contributors can inject persistent JavaScript into WordPress pages, executing arbitrary scripts in the browsers of all visitors, including administrators.

Affected Products

  • aThemes Addons for Elementor (Lite) WordPress plugin
  • All versions up to and including 1.1.2
  • WordPress sites running the plugin with contributor-level accounts or higher

Discovery Timeline

  • 2025-09-06 - CVE-2025-8149 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8149

Vulnerability Analysis

The vulnerability is a Stored Cross-Site Scripting flaw in the Countdown widget shipped with the aThemes Addons for Elementor plugin. The widget accepts user-supplied attributes when configured in the Elementor page builder. These attributes are neither sanitized on input nor escaped on output when the widget renders. As a result, an attacker with the WordPress contributor role can embed JavaScript payloads into widget attributes and persist them in the database. When any visitor renders the page, the payload executes with the visitor's session context.

Stored XSS in a page-building context is particularly useful to attackers because the injected content survives across sessions and executes for every viewer. A payload targeting an administrator session can invoke privileged REST endpoints, create new admin users, or install malicious plugins, escalating a low-privilege foothold into full site compromise.

Root Cause

The root cause is missing input sanitization and missing output escaping in the Countdown widget's attribute handling logic. WordPress provides helpers such as sanitize_text_field(), wp_kses_post(), and esc_attr() / esc_html() for this purpose, but the vulnerable code paths did not apply them to the affected widget attributes before rendering markup.

Attack Vector

Exploitation requires an authenticated account with at least contributor privileges. The attacker edits or creates a post containing an Elementor Countdown widget and supplies a malicious value in one of the widget's attribute fields. On save, the payload is stored in wp_postmeta. When a visitor loads the post, the widget renders and the browser executes the injected script within the site's origin.

Because the impact scope changes (S:C), the executed script can affect resources beyond the vulnerable widget itself, including cookies, DOM state of the admin interface, and any authenticated session context reachable from the page origin.

No verified public exploit code is available. Refer to the Wordfence Vulnerability Report and the WordPress Plugin Changeset for the vendor's fix diff.

Detection Methods for CVE-2025-8149

Indicators of Compromise

  • Post or page metadata (wp_postmeta) containing <script>, onerror=, onload=, or javascript: strings within Elementor Countdown widget attributes.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains after loading pages that use the Countdown widget.
  • New WordPress administrator accounts or plugin installations created shortly after a contributor edited a page containing the Countdown widget.

Detection Strategies

  • Query the wp_postmeta table for Elementor _elementor_data entries containing HTML event handlers or <script tokens.
  • Enable and review WordPress audit logs for post edits by contributor-level accounts that include Countdown widget usage.
  • Deploy a Content Security Policy (CSP) in report-only mode to surface inline script execution originating from post content.

Monitoring Recommendations

  • Alert on privilege changes, plugin installations, and REST API calls to /wp-json/wp/v2/users following contributor activity.
  • Monitor Elementor widget rendering endpoints for anomalous response payloads containing script tags.
  • Track browser console errors and CSP violation reports for pages that embed the Countdown widget.

How to Mitigate CVE-2025-8149

Immediate Actions Required

  • Update the aThemes Addons for Elementor plugin to a version later than 1.1.2 that includes the fix from changeset 3350397.
  • Audit all pages built with Elementor for Countdown widget usage and review attribute values for injected script content.
  • Restrict contributor and author accounts to trusted users only, and reset credentials for accounts suspected of compromise.

Patch Information

The vendor addressed the issue in the plugin update reflected in WordPress.org plugin changeset 3350397. Site administrators should install the latest version through the WordPress plugin dashboard or by downloading it from the aThemes Addons for Elementor plugin page. Verify the installed version is above 1.1.2 after upgrade.

Workarounds

  • Temporarily deactivate the aThemes Addons for Elementor plugin until the patched version is deployed.
  • Remove the Countdown widget from published pages and disable it within Elementor's widget settings if deactivation is not feasible.
  • Restrict the edit_posts capability for untrusted contributor accounts, or move those accounts to a role without post-editing rights until patching is complete.
bash
# Verify installed plugin version via WP-CLI
wp plugin get athemes-addons-for-elementor-lite --field=version

# Update the plugin to the latest patched release
wp plugin update athemes-addons-for-elementor-lite

# Temporarily deactivate if patching must be delayed
wp plugin deactivate athemes-addons-for-elementor-lite

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.