CVE-2025-8867 Overview
CVE-2025-8867 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the Graphina - Elementor Charts and Graphs plugin for WordPress. The flaw affects version 3.1.3 and below. Insufficient input sanitization and output escaping on chart widget parameters allow authenticated attackers with contributor-level access or higher to inject arbitrary JavaScript. Injected scripts execute whenever any user views the affected page. The vulnerable inputs include chart categories, titles, and tooltip settings across multiple ApexCharts widgets exposed by the plugin.
Critical Impact
Contributor-level users can persist JavaScript payloads inside chart widgets that execute in the browsers of site visitors and administrators, enabling session theft, forced actions, and site defacement.
Affected Products
- Graphina - Elementor Charts and Graphs plugin for WordPress, versions ≤ 3.1.3
- WordPress sites using Elementor with the Graphina plugin installed
- All Graphina ApexCharts widgets, including AreaChart, ColumnChart, DistributeColumnChart, HeatmapChart, LineChart, RadarChart, ScatterChart, and TimelineChart
Discovery Timeline
- 2025-08-15 - CVE-2025-8867 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8867
Vulnerability Analysis
The Graphina plugin renders user-supplied chart configuration values directly into page output without adequate sanitization or escaping. Because contributors can add and edit Elementor widgets, they can supply attacker-controlled strings to attributes such as chart categories, titles, and tooltip content. Those strings are stored in post metadata and later reflected into HTML or inline JavaScript when the chart widget renders. The result is persistent script execution in the browsers of anyone visiting the affected page, including editors and administrators.
Root Cause
The root cause is a missing output-escaping layer inside the ApexCharts widget classes. The vulnerable render paths are documented across multiple widget files in the plugin trunk, including AreaChart.php, ColumnChart.php, DistributeColumnChart.php, HeatmapChart.php, LineChart.php, RadarChart.php, ScatterChart.php, and TimelineChart.php. Each of these locations concatenates operator-supplied values into the chart configuration without WordPress escaping helpers such as esc_html, esc_attr, or wp_kses. See the Wordfence Vulnerability Report for the full disclosure and the WordPress Graphina Changeset Overview for the applied fix.
Attack Vector
An authenticated attacker with contributor privileges creates or edits a page using a Graphina chart widget. The attacker enters a JavaScript payload into a susceptible field such as the chart title or a category label. When the page is later rendered, the payload executes in the visitor's browser under the site's origin. The attack requires no user interaction beyond viewing the page. In WordPress workflows where an editor or administrator reviews pending contributor content, the payload can execute in a privileged session and be used to escalate access.
Detection Methods for CVE-2025-8867
Indicators of Compromise
- Chart widget attributes in wp_postmeta containing HTML tags such as <script>, <img onerror=...>, or <svg onload=...>
- Unexpected outbound requests from browsers rendering pages that embed Graphina charts
- New administrator accounts or modified user roles created shortly after a contributor edited a page containing a Graphina widget
- Elementor revisions authored by contributor accounts that add unusual characters to chart categories, titles, or tooltips
Detection Strategies
- Query the WordPress database for Graphina widget settings and flag entries where chart parameter strings contain angle brackets, javascript: URIs, or event-handler attributes
- Enable and review Elementor and WordPress audit logs to identify contributor accounts editing chart widgets
- Monitor web server logs for POST requests to admin-ajax.php and the Elementor editor endpoints originating from low-privilege accounts
Monitoring Recommendations
- Alert on any contributor or author account that publishes or updates content containing Graphina widgets
- Deploy a Content Security Policy (CSP) and monitor CSP violation reports for inline script execution on pages using Graphina
- Track anomalous administrator session activity, such as role changes or plugin installs, following contributor content submissions
How to Mitigate CVE-2025-8867
Immediate Actions Required
- Update the Graphina - Elementor Charts and Graphs plugin to a version above 3.1.3
- Audit all pages containing Graphina chart widgets for suspicious markup in categories, titles, and tooltip fields
- Review contributor, author, and editor accounts and remove any that are not required or that show signs of compromise
- Rotate credentials for administrator and editor accounts that may have viewed attacker-controlled pages
Patch Information
The vendor addressed the vulnerability in a release above version 3.1.3. The corresponding source changes are recorded in the WordPress Graphina Changeset Overview. Administrators should apply the update through the WordPress plugin dashboard or via WP-CLI.
Workarounds
- Restrict contributor-and-above access on sites that cannot immediately update the plugin
- Deactivate the Graphina plugin on pages that expose contributor editing until the patched version is installed
- Deploy a Web Application Firewall (WAF) rule that blocks HTML tags and JavaScript event handlers in Elementor widget POST parameters
- Enforce a strict CSP that disallows inline scripts to reduce the impact of stored payloads
# Update Graphina via WP-CLI to remediate CVE-2025-8867
wp plugin update graphina-elementor-charts-and-graphs
wp plugin get graphina-elementor-charts-and-graphs --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
