Skip to main content

CVE-2025-9075: ZoloBlocks WordPress Plugin XSS Vulnerability

CVE-2025-9075 is a stored XSS vulnerability in the ZoloBlocks WordPress plugin affecting multiple Gutenberg blocks. Authenticated attackers can inject malicious scripts that execute when users view affected pages. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-9075 Overview

CVE-2025-9075 is a stored Cross-Site Scripting (XSS) vulnerability in the ZoloBlocks plugin for WordPress, affecting all versions up to and including 2.3.10. The flaw resides in multiple Gutenberg block components, including Google Maps markers, Lightbox captions, Image Gallery data attributes, Progress Pie prefix and suffix fields, and Text Path URL fields. Insufficient input sanitization and output escaping on user-supplied block attributes allow authenticated attackers with contributor-level access or above to inject arbitrary JavaScript. Injected scripts execute in the browser of any user who visits an affected page. The issue is tracked under CWE-79.

Critical Impact

Contributor-level users can persist JavaScript that runs in the context of site visitors and administrators, enabling session hijacking, credential theft, and administrative account takeover.

Affected Products

  • ZoloBlocks plugin for WordPress, versions ≤ 2.3.10
  • WordPress sites permitting contributor-level user registration with ZoloBlocks installed
  • Any published page or post rendering vulnerable ZoloBlocks Gutenberg blocks

Discovery Timeline

  • 2025-10-01 - CVE-2025-9075 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9075

Vulnerability Analysis

The vulnerability affects multiple front-end block renderers shipped with ZoloBlocks. Each vulnerable block accepts attributes controlled by the post author and writes them into the DOM without adequate sanitization or escaping. Because the injection is stored inside post content, the payload persists across sessions and executes for every visitor who loads the affected page. Contributors in WordPress can create posts but require editor approval to publish. Even so, injected scripts execute when editors or administrators preview pending posts, enabling privilege escalation through session theft or forced administrative actions.

Root Cause

The root cause is missing input sanitization and output escaping in the front-end JavaScript renderers for the Google Maps, Lightbox, Image Gallery, Progress Pie, and Text Path blocks. User-supplied attribute values are concatenated into HTML or passed to sinks that interpret markup, rather than being escaped with WordPress helpers such as esc_html, esc_attr, or wp_kses. The vulnerable renderers are visible in the plugin sources for Google Map, Image Gallery, Progress Pie, and Text Path.

Attack Vector

An authenticated contributor edits a post and inserts one of the vulnerable ZoloBlocks blocks. The attacker sets a targeted attribute, such as a Google Maps marker description, a Lightbox caption, an Image Gallery data attribute, a Progress Pie prefix or suffix, or a Text Path URL, to a value containing HTML or JavaScript. When the post is previewed or published, the plugin injects the payload into the rendered page. The script executes in the browser of any authenticated reviewer or unauthenticated visitor, with access to cookies, session tokens, and administrative UI actions in the current origin.

No verified public proof-of-concept code has been released. See the Wordfence Vulnerability Report for additional technical detail.

Detection Methods for CVE-2025-9075

Indicators of Compromise

  • Post or page content containing ZoloBlocks block markup with attribute values that include <script>, onerror=, onload=, or javascript: sequences.
  • Unexpected outbound HTTP requests from visitor browsers to attacker-controlled domains sourced from pages rendering ZoloBlocks blocks.
  • New or modified posts authored by contributor-level accounts that were recently registered or previously inactive.
  • Administrator session cookies observed in web server access logs originating from unusual IP addresses shortly after ZoloBlocks pages are viewed.

Detection Strategies

  • Query the wp_posts table for ZoloBlocks block comments (for example, wp:zoloblocks/) with attribute payloads containing HTML tags or event handlers.
  • Inspect rendered HTML for the vulnerable blocks and flag responses where user-controlled attributes contain executable markup.
  • Enable a Content Security Policy in report-only mode and review violation reports for inline script executions originating from post content.

Monitoring Recommendations

  • Audit WordPress role assignments and monitor creation of contributor and author accounts.
  • Log and alert on plugin file changes and on posts edited by non-editor roles that contain ZoloBlocks markup.
  • Forward WordPress and web server logs to a central analytics platform to correlate contributor activity with anomalous script execution.

How to Mitigate CVE-2025-9075

Immediate Actions Required

  • Update the ZoloBlocks plugin to a version later than 2.3.10 that incorporates the fixes in changesets 3351996 and 3369092.
  • Review all posts and pages authored by contributor-level accounts for injected script content and revert or sanitize any suspect entries.
  • Rotate administrator and editor credentials and invalidate active sessions if injected scripts may have executed in privileged browsers.

Patch Information

The vendor addressed the flaw in ZoloBlocks releases following version 2.3.10. The relevant commits are changeset 3351996 and changeset 3369092, which introduce sanitization and escaping for the affected block attributes. Site owners should apply the update through the WordPress plugin manager or by deploying the patched release from the WordPress plugin repository.

Workarounds

  • Disable the ZoloBlocks plugin until the patched version can be deployed.
  • Restrict contributor and author roles to trusted users and require editorial review before publishing content that uses ZoloBlocks blocks.
  • Deploy a web application firewall rule to block requests containing script tags or JavaScript event handlers in ZoloBlocks block attributes.
  • Implement a strict Content Security Policy that disallows inline scripts on public-facing pages.
bash
# Update ZoloBlocks via WP-CLI on the affected host
wp plugin update zoloblocks
wp plugin get zoloblocks --field=version

# Optional: temporarily deactivate the plugin until patched
wp plugin deactivate zoloblocks

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.