Skip to main content

CVE-2025-9077: Ultra Addons Lite for Elementor XSS Flaw

CVE-2025-9077 is a stored cross-site scripting vulnerability in Ultra Addons Lite for Elementor plugin for WordPress that allows authenticated attackers to inject malicious scripts. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2025-9077 Overview

CVE-2025-9077 is a Stored Cross-Site Scripting (XSS) vulnerability in the Ultra Addons Lite for Elementor plugin for WordPress. The flaw resides in the Animated Text field of the Typeout Widget in versions 1.1.9 and below. Insufficient input sanitization and output escaping allow authenticated users with contributor-level access or higher to inject arbitrary JavaScript. The injected script executes in the browser of any user who visits an affected page. The vulnerability is tracked under CWE-79 and was published to the National Vulnerability Database (NVD) on October 3, 2025.

Critical Impact

Authenticated contributors can persist malicious scripts into published pages, enabling session theft, administrative account takeover, and drive-by redirects against site visitors and editors.

Affected Products

  • Ultra Addons Lite for Elementor plugin for WordPress, versions 1.1.9 and earlier
  • WordPress sites that expose contributor-level (or higher) registration or accounts
  • Sites rendering the Typeout Widget on public-facing pages

Discovery Timeline

  • 2025-10-03 - CVE-2025-9077 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9077

Vulnerability Analysis

The Ultra Addons Lite for Elementor plugin ships a Typeout Widget that renders an Animated Text field controlled by the page editor. In vulnerable builds, the widget passes user-supplied content to the page output without sufficient sanitization or escaping. Any authenticated user permitted to edit pages, including WordPress contributors, can insert HTML and JavaScript into the field. When another user loads the page, the browser interprets the payload in the context of the site origin.

The issue is a stored XSS variant because the payload persists in the WordPress post or postmeta database and executes on every subsequent page load. Contributors normally submit drafts for review, but the payload activates as soon as an editor previews the page or an administrator publishes it. Successful exploitation can hijack authenticated sessions, create rogue administrator accounts, or pivot into further plugin abuse. Because the vulnerable rendering path executes in the visitor's browser rather than on the server, standard WordPress role restrictions do not contain the impact.

Root Cause

The root cause is missing sanitization on input and missing escaping on output for the Animated Text widget field. The rendering code path in elements/typeout.php around line 276 concatenates the attacker-controlled value into HTML without functions such as esc_html(), esc_attr(), or wp_kses(). See the WordPress Plugin Code Review 1.1.9 and WordPress Plugin Code Review 1.2.0 for the exact code locations.

Attack Vector

An authenticated attacker with contributor privileges edits an Elementor page and adds a Typeout Widget. The attacker enters a JavaScript payload into the Animated Text field and saves the draft. When a higher-privileged user previews, publishes, or visits the page, the browser executes the payload under the site's origin. The attack requires network access to the WordPress admin, low privileges, and no user interaction beyond visiting the page. See the Wordfence Vulnerability Report for additional context.

No public proof-of-concept code is required to describe the mechanism. Any standard XSS payload placed inside the Animated Text string is stored verbatim and rendered inside the page markup emitted by the Typeout Widget.

Detection Methods for CVE-2025-9077

Indicators of Compromise

  • Post or postmeta rows containing <script>, onerror=, onload=, or javascript: strings within Elementor Typeout Widget data
  • Unexpected outbound requests from editor or visitor browsers to attacker-controlled domains after loading a page with a Typeout Widget
  • New WordPress administrator accounts or role changes shortly after a contributor edits a page containing the Typeout Widget
  • Contributor accounts publishing or updating Elementor pages that include the ultimate-typeout or Typeout widget class

Detection Strategies

  • Scan wp_postmeta for _elementor_data entries containing the Typeout widget with HTML tags or event handlers in the animated_text field
  • Enable WordPress activity logging to record post revisions by contributor accounts and correlate with widget usage
  • Deploy a web application firewall rule that flags stored payloads containing script tags or event handlers submitted to admin-ajax.php Elementor save endpoints
  • Alert on browser Content Security Policy (CSP) violations originating from pages that embed the Typeout Widget

Monitoring Recommendations

  • Monitor plugin version inventory across managed WordPress sites and flag installations of Ultra Addons Lite for Elementor at or below 1.1.9
  • Track contributor-role account creation, especially self-registration on sites where new user registration is enabled
  • Review admin-user audit logs daily for unexpected role escalations or password changes following page edits

How to Mitigate CVE-2025-9077

Immediate Actions Required

  • Update the Ultra Addons Lite for Elementor plugin to version 1.2.0 or later on all affected WordPress installations
  • Audit existing pages that use the Typeout Widget and remove any suspicious payloads from the Animated Text field
  • Restrict contributor and author account creation, and review recent registrations for signs of abuse
  • Rotate credentials and session tokens for any administrator who previewed or published a suspect page

Patch Information

The plugin author addressed the issue in version 1.2.0. Site operators should upgrade through the WordPress plugin manager or via WP-CLI. Compare the vulnerable 1.1.9 source with the fixed 1.2.0 source to verify the sanitization change on managed forks.

Workarounds

  • Disable the Ultra Addons Lite for Elementor plugin until the site can be upgraded to 1.2.0
  • Remove the Typeout Widget from all published pages if the plugin cannot be uninstalled immediately
  • Restrict edit access to trusted authors and disable open user registration to reduce the attacker pool
  • Deploy a Content Security Policy that blocks inline scripts to reduce the impact of any stored XSS payload
bash
# Upgrade the vulnerable plugin using WP-CLI
wp plugin update ut-elementor-addons-lite --version=1.2.0

# Verify installed version
wp plugin get ut-elementor-addons-lite --field=version

# Temporary workaround: deactivate the plugin
wp plugin deactivate ut-elementor-addons-lite

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.