CVE-2025-9204 Overview
CVE-2025-9204 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the X Addons for Elementor plugin for WordPress. The flaw affects all versions up to and including 1.0.16. It exists in the Youtube Video ID field of the plugin's Hero widget, where input sanitization and output escaping are insufficient.
Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The payload executes in the browser of any visitor who loads the affected page. This creates opportunities for session theft, admin account takeover, and further compromise of the WordPress site.
Critical Impact
Authenticated contributors can persist arbitrary JavaScript in published pages, enabling session hijacking against site administrators and visitors.
Affected Products
- X Addons for Elementor WordPress plugin, all versions up to and including 1.0.16
- WordPress sites running the vulnerable plugin with contributor-level or higher accounts
- Elementor-based pages using the plugin's Hero widget (xa-hero)
Discovery Timeline
- 2025-10-03 - CVE-2025-9204 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9204
Vulnerability Analysis
The vulnerability resides in the Hero widget component of the X Addons for Elementor plugin, specifically at includes/widgets/xa-hero.php around line 723 in the 1.0.14 tag. The Youtube Video ID parameter accepts user-controlled input but does not sanitize it on save or escape it on render.
An attacker with contributor privileges can supply a crafted value in the Youtube Video ID field. The input is stored in the post's Elementor data and later reflected into the page markup when the widget renders. Because the value is placed into an HTML context without proper escaping, JavaScript payloads execute in the context of the site's origin.
Stored XSS in a WordPress environment is particularly useful to adversaries because contributor accounts are common on multi-author sites. Payloads execute against editors and administrators who preview or publish content, enabling privilege escalation through cookie theft, forced actions via the REST API, or injection of malicious redirects.
Root Cause
The plugin fails to apply WordPress sanitization functions such as sanitize_text_field() on input, and it does not use esc_attr() or esc_html() when rendering the Youtube Video ID value into the widget output. See the WordPress Plugin Widget Code for the vulnerable rendering path.
Attack Vector
Exploitation requires an authenticated session with contributor role or higher. The attacker edits a page or post using the Elementor editor, adds the plugin's Hero widget, and inserts a JavaScript payload into the Youtube Video ID field. When the page is viewed by any user, including administrators, the script executes in their browser.
No verified public proof-of-concept code is available. Refer to the Wordfence Vulnerability Report for additional technical context.
Detection Methods for CVE-2025-9204
Indicators of Compromise
- Elementor post metadata (_elementor_data) containing <script>, onerror=, onload=, or javascript: strings within youtube_id or Hero widget settings
- New or modified WordPress administrator accounts created shortly after contributor activity on Hero widget pages
- Unexpected outbound requests from visitor browsers to attacker-controlled domains referenced on plugin-rendered pages
Detection Strategies
- Query the wp_postmeta table for Hero widget entries and inspect the youtube_id field for HTML or JavaScript characters
- Review WordPress audit logs for contributor accounts editing or publishing pages that use the X Addons Hero widget
- Scan rendered page HTML for inline script tags or event handlers originating from plugin widget containers
Monitoring Recommendations
- Enable a WordPress activity logging plugin to track post edits by non-administrator roles
- Alert on any modification to _elementor_data post meta containing script-like patterns
- Monitor browser Content Security Policy (CSP) violation reports for inline script executions on pages using the plugin
How to Mitigate CVE-2025-9204
Immediate Actions Required
- Update the X Addons for Elementor plugin to a version later than 1.0.16 once released by the vendor
- Audit all contributor, author, and editor accounts and remove unnecessary privileges
- Review pages using the Hero widget for suspicious payloads in the Youtube Video ID field and remove any injected content
Patch Information
The vendor addressed related code in WordPress Plugin Changeset #3375643. Site administrators should install the patched release from the WordPress plugin repository and validate the installed version is above 1.0.16.
Workarounds
- Restrict contributor and author roles until the plugin is updated, or temporarily deactivate the X Addons for Elementor plugin
- Deploy a Web Application Firewall (WAF) rule that blocks script tags and JavaScript event handlers in Elementor widget parameters
- Implement a strict Content Security Policy that disallows inline scripts on pages served by WordPress
# Content Security Policy header example for Apache
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.