Skip to main content

CVE-2025-8685: WordPress WP Chart Generator XSS Flaw

CVE-2025-8685 is a stored cross-site scripting vulnerability in the WP Chart Generator WordPress plugin affecting versions up to 1.0.4. Attackers with contributor access can inject malicious scripts via the wpchart shortcode. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-8685 Overview

CVE-2025-8685 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Chart Generator plugin for WordPress. The flaw affects all versions up to and including 1.0.4. It stems from insufficient input sanitization and output escaping on user-supplied attributes passed to the plugin's wpchart shortcode. Authenticated attackers with contributor-level access or above can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor who views the affected page. The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.

Critical Impact

Contributor-level users can inject persistent JavaScript that runs in visitors' browsers, enabling session theft, forced redirects, and administrative account takeover if an admin views the injected content.

Affected Products

  • WordPress plugin: WP Chart Generator, all versions ≤ 1.0.4
  • WordPress sites permitting contributor-level registration or above
  • Any page or post rendering the wpchart shortcode with attacker-controlled attributes

Discovery Timeline

  • 2025-08-12 - CVE-2025-8685 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8685

Vulnerability Analysis

The WP Chart Generator plugin exposes a wpchart shortcode that accepts user-supplied attributes to render charts inside WordPress posts and pages. The plugin does not sanitize these attribute values on input and does not escape them on output. As a result, arbitrary HTML and JavaScript payloads embedded in shortcode attributes are written directly into rendered page markup.

Because the payload is stored in post content, it persists in the WordPress database. Every subsequent visitor to the affected page executes the attacker's script in their browser session. This is a stored XSS pattern, not reflected, so no social engineering step is required to trigger execution.

The impact scope is Changed under CVSS: script execution occurs in the visitor's browser context, allowing session cookie theft, forced administrative actions, redirection to malicious sites, and pivoting toward full site compromise if a site administrator views the injected content.

Root Cause

The root cause is the absence of two WordPress-standard security controls in the shortcode handler. Attribute values are not passed through sanitization functions such as sanitize_text_field() or wp_kses() on input. Values are not escaped through esc_attr(), esc_html(), or esc_js() before being emitted into HTML. This dual failure allows raw attacker-supplied markup to reach the rendered DOM.

Attack Vector

The attack requires an authenticated account with contributor privileges or higher. An attacker creates a post or page containing the wpchart shortcode with a malicious attribute value carrying JavaScript. When the post is previewed, submitted for review, or published and later viewed by any user, including editors and administrators, the injected script executes. See the Wordfence Vulnerability Analysis and the WordPress Plugin Source Code for the affected handler.

// No verified exploit code is published. The vulnerability is triggered by
// supplying JavaScript payloads inside attributes of the [wpchart] shortcode,
// which are rendered into page HTML without sanitization or escaping.

Detection Methods for CVE-2025-8685

Indicators of Compromise

  • Post or page content containing [wpchart ...] shortcodes with attribute values that include <script>, onerror=, onload=, javascript:, or encoded equivalents.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains sourced from pages rendering wpchart.
  • New or modified administrator accounts, plugin installations, or option changes shortly after a contributor-authored post is viewed by an admin.

Detection Strategies

  • Query the wp_posts table for post_content matching wpchart combined with common XSS tokens to surface injected payloads.
  • Review WordPress audit logs for contributor accounts submitting or updating posts that include the wpchart shortcode.
  • Inspect web server access logs for referer chains where administrative endpoints are hit immediately after rendering a page containing wpchart.

Monitoring Recommendations

  • Alert on creation of new administrator users or role changes performed from admin sessions that recently rendered a post with the wpchart shortcode.
  • Monitor Content Security Policy (CSP) violation reports for inline script executions on pages using the plugin.
  • Track plugin version inventory across WordPress sites and flag any instance of WP Chart Generator at version 1.0.4 or earlier.

How to Mitigate CVE-2025-8685

Immediate Actions Required

  • Deactivate and remove the WP Chart Generator plugin until a patched release is available and verified.
  • Audit all existing posts and pages for wpchart shortcodes and inspect their attributes for injected script content.
  • Restrict contributor-level and higher account creation, and review recent registrations for suspicious accounts.
  • Rotate credentials and invalidate active sessions for administrator accounts that may have viewed injected pages.

Patch Information

No fixed version is listed in the NVD entry at the time of publication. Monitor the WordPress Plugin Developer Page for a release addressing this issue and apply the update as soon as it is published. Confirm the fixed version through the Wordfence Vulnerability Analysis before returning the plugin to production.

Workarounds

  • Disable the plugin site-wide until a patched version is confirmed.
  • Limit posting privileges to trusted editors and administrators; block contributor-tier registration.
  • Deploy a web application firewall rule that blocks shortcode attribute values containing <script, on\w+=, or javascript: patterns.
  • Enforce a strict Content Security Policy that disallows inline scripts on pages served by WordPress.
bash
# Disable the vulnerable plugin from the command line using WP-CLI
wp plugin deactivate wp-chart-generator
wp plugin delete wp-chart-generator

# Search post content for the vulnerable shortcode
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%[wpchart%';"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.