CVE-2025-8685 Overview
CVE-2025-8685 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Chart Generator plugin for WordPress. The flaw affects all versions up to and including 1.0.4. It stems from insufficient input sanitization and output escaping on user-supplied attributes passed to the plugin's wpchart shortcode. Authenticated attackers with contributor-level access or above can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor who views the affected page. The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Contributor-level users can inject persistent JavaScript that runs in visitors' browsers, enabling session theft, forced redirects, and administrative account takeover if an admin views the injected content.
Affected Products
- WordPress plugin: WP Chart Generator, all versions ≤ 1.0.4
- WordPress sites permitting contributor-level registration or above
- Any page or post rendering the wpchart shortcode with attacker-controlled attributes
Discovery Timeline
- 2025-08-12 - CVE-2025-8685 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8685
Vulnerability Analysis
The WP Chart Generator plugin exposes a wpchart shortcode that accepts user-supplied attributes to render charts inside WordPress posts and pages. The plugin does not sanitize these attribute values on input and does not escape them on output. As a result, arbitrary HTML and JavaScript payloads embedded in shortcode attributes are written directly into rendered page markup.
Because the payload is stored in post content, it persists in the WordPress database. Every subsequent visitor to the affected page executes the attacker's script in their browser session. This is a stored XSS pattern, not reflected, so no social engineering step is required to trigger execution.
The impact scope is Changed under CVSS: script execution occurs in the visitor's browser context, allowing session cookie theft, forced administrative actions, redirection to malicious sites, and pivoting toward full site compromise if a site administrator views the injected content.
Root Cause
The root cause is the absence of two WordPress-standard security controls in the shortcode handler. Attribute values are not passed through sanitization functions such as sanitize_text_field() or wp_kses() on input. Values are not escaped through esc_attr(), esc_html(), or esc_js() before being emitted into HTML. This dual failure allows raw attacker-supplied markup to reach the rendered DOM.
Attack Vector
The attack requires an authenticated account with contributor privileges or higher. An attacker creates a post or page containing the wpchart shortcode with a malicious attribute value carrying JavaScript. When the post is previewed, submitted for review, or published and later viewed by any user, including editors and administrators, the injected script executes. See the Wordfence Vulnerability Analysis and the WordPress Plugin Source Code for the affected handler.
// No verified exploit code is published. The vulnerability is triggered by
// supplying JavaScript payloads inside attributes of the [wpchart] shortcode,
// which are rendered into page HTML without sanitization or escaping.
Detection Methods for CVE-2025-8685
Indicators of Compromise
- Post or page content containing [wpchart ...] shortcodes with attribute values that include <script>, onerror=, onload=, javascript:, or encoded equivalents.
- Unexpected outbound requests from visitor browsers to attacker-controlled domains sourced from pages rendering wpchart.
- New or modified administrator accounts, plugin installations, or option changes shortly after a contributor-authored post is viewed by an admin.
Detection Strategies
- Query the wp_posts table for post_content matching wpchart combined with common XSS tokens to surface injected payloads.
- Review WordPress audit logs for contributor accounts submitting or updating posts that include the wpchart shortcode.
- Inspect web server access logs for referer chains where administrative endpoints are hit immediately after rendering a page containing wpchart.
Monitoring Recommendations
- Alert on creation of new administrator users or role changes performed from admin sessions that recently rendered a post with the wpchart shortcode.
- Monitor Content Security Policy (CSP) violation reports for inline script executions on pages using the plugin.
- Track plugin version inventory across WordPress sites and flag any instance of WP Chart Generator at version 1.0.4 or earlier.
How to Mitigate CVE-2025-8685
Immediate Actions Required
- Deactivate and remove the WP Chart Generator plugin until a patched release is available and verified.
- Audit all existing posts and pages for wpchart shortcodes and inspect their attributes for injected script content.
- Restrict contributor-level and higher account creation, and review recent registrations for suspicious accounts.
- Rotate credentials and invalidate active sessions for administrator accounts that may have viewed injected pages.
Patch Information
No fixed version is listed in the NVD entry at the time of publication. Monitor the WordPress Plugin Developer Page for a release addressing this issue and apply the update as soon as it is published. Confirm the fixed version through the Wordfence Vulnerability Analysis before returning the plugin to production.
Workarounds
- Disable the plugin site-wide until a patched version is confirmed.
- Limit posting privileges to trusted editors and administrators; block contributor-tier registration.
- Deploy a web application firewall rule that blocks shortcode attribute values containing <script, on\w+=, or javascript: patterns.
- Enforce a strict Content Security Policy that disallows inline scripts on pages served by WordPress.
# Disable the vulnerable plugin from the command line using WP-CLI
wp plugin deactivate wp-chart-generator
wp plugin delete wp-chart-generator
# Search post content for the vulnerable shortcode
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%[wpchart%';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.