Skip to main content

CVE-2025-9204: X Addons for Elementor XSS Vulnerability

CVE-2025-9204 is a stored cross-site scripting vulnerability in X Addons for Elementor WordPress plugin that lets authenticated attackers inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-9204 Overview

CVE-2025-9204 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the X Addons for Elementor plugin for WordPress. The flaw affects all versions up to and including 1.0.16. It exists in the Youtube Video ID field of the plugin's Hero widget, where input sanitization and output escaping are insufficient.

Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The payload executes in the browser of any visitor who loads the affected page. This creates opportunities for session theft, admin account takeover, and further compromise of the WordPress site.

Critical Impact

Authenticated contributors can persist arbitrary JavaScript in published pages, enabling session hijacking against site administrators and visitors.

Affected Products

  • X Addons for Elementor WordPress plugin, all versions up to and including 1.0.16
  • WordPress sites running the vulnerable plugin with contributor-level or higher accounts
  • Elementor-based pages using the plugin's Hero widget (xa-hero)

Discovery Timeline

  • 2025-10-03 - CVE-2025-9204 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9204

Vulnerability Analysis

The vulnerability resides in the Hero widget component of the X Addons for Elementor plugin, specifically at includes/widgets/xa-hero.php around line 723 in the 1.0.14 tag. The Youtube Video ID parameter accepts user-controlled input but does not sanitize it on save or escape it on render.

An attacker with contributor privileges can supply a crafted value in the Youtube Video ID field. The input is stored in the post's Elementor data and later reflected into the page markup when the widget renders. Because the value is placed into an HTML context without proper escaping, JavaScript payloads execute in the context of the site's origin.

Stored XSS in a WordPress environment is particularly useful to adversaries because contributor accounts are common on multi-author sites. Payloads execute against editors and administrators who preview or publish content, enabling privilege escalation through cookie theft, forced actions via the REST API, or injection of malicious redirects.

Root Cause

The plugin fails to apply WordPress sanitization functions such as sanitize_text_field() on input, and it does not use esc_attr() or esc_html() when rendering the Youtube Video ID value into the widget output. See the WordPress Plugin Widget Code for the vulnerable rendering path.

Attack Vector

Exploitation requires an authenticated session with contributor role or higher. The attacker edits a page or post using the Elementor editor, adds the plugin's Hero widget, and inserts a JavaScript payload into the Youtube Video ID field. When the page is viewed by any user, including administrators, the script executes in their browser.

No verified public proof-of-concept code is available. Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2025-9204

Indicators of Compromise

  • Elementor post metadata (_elementor_data) containing <script>, onerror=, onload=, or javascript: strings within youtube_id or Hero widget settings
  • New or modified WordPress administrator accounts created shortly after contributor activity on Hero widget pages
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains referenced on plugin-rendered pages

Detection Strategies

  • Query the wp_postmeta table for Hero widget entries and inspect the youtube_id field for HTML or JavaScript characters
  • Review WordPress audit logs for contributor accounts editing or publishing pages that use the X Addons Hero widget
  • Scan rendered page HTML for inline script tags or event handlers originating from plugin widget containers

Monitoring Recommendations

  • Enable a WordPress activity logging plugin to track post edits by non-administrator roles
  • Alert on any modification to _elementor_data post meta containing script-like patterns
  • Monitor browser Content Security Policy (CSP) violation reports for inline script executions on pages using the plugin

How to Mitigate CVE-2025-9204

Immediate Actions Required

  • Update the X Addons for Elementor plugin to a version later than 1.0.16 once released by the vendor
  • Audit all contributor, author, and editor accounts and remove unnecessary privileges
  • Review pages using the Hero widget for suspicious payloads in the Youtube Video ID field and remove any injected content

Patch Information

The vendor addressed related code in WordPress Plugin Changeset #3375643. Site administrators should install the patched release from the WordPress plugin repository and validate the installed version is above 1.0.16.

Workarounds

  • Restrict contributor and author roles until the plugin is updated, or temporarily deactivate the X Addons for Elementor plugin
  • Deploy a Web Application Firewall (WAF) rule that blocks script tags and JavaScript event handlers in Elementor widget parameters
  • Implement a strict Content Security Policy that disallows inline scripts on pages served by WordPress
bash
# Content Security Policy header example for Apache
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.