Skip to main content

CVE-2025-9698: Plus Addons for Elementor XSS Vulnerability

CVE-2025-9698 is a stored cross-site scripting flaw in Plus Addons for Elementor WordPress plugin affecting versions before 6.3.16. Authors can exploit unsanitized SVG uploads to inject malicious scripts. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-9698 Overview

CVE-2025-9698 is a Stored Cross-Site Scripting (XSS) vulnerability in The Plus Addons for Elementor WordPress plugin. Versions prior to 6.3.16 fail to sanitize the contents of uploaded SVG files. An authenticated user with Author-level access or higher can upload a crafted SVG that executes arbitrary JavaScript when rendered in a victim's browser.

The flaw enables session hijacking, credential theft, and administrative account takeover when a higher-privileged user views the malicious media. Because Author is a low-trust role on many WordPress sites that accept contributor content, the barrier to exploitation is limited to obtaining or compromising a single content-producing account.

Critical Impact

An authenticated Author can plant persistent JavaScript in an SVG that executes against administrators, leading to full site compromise.

Affected Products

  • The Plus Addons for Elementor WordPress plugin, all versions before 6.3.16
  • WordPress sites permitting SVG uploads through the plugin
  • Sites where Author-level or higher accounts exist and can be provisioned or compromised

Discovery Timeline

  • 2025-10-13 - CVE-2025-9698 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9698

Vulnerability Analysis

The vulnerability is a Stored Cross-Site Scripting weakness triggered through unsanitized Scalable Vector Graphics (SVG) file uploads. SVG is an XML-based image format that natively supports <script> elements and event handlers such as onload and onclick. When a web application accepts SVG files without stripping executable content, any embedded JavaScript runs in the origin of the hosting site.

The Plus Addons for Elementor accepts SVG uploads from users with Author role or above but does not pass file contents through a sanitizer such as enshrined/svg-sanitize. The malicious payload persists in the WordPress media library and executes whenever an authenticated user, including an administrator, opens or previews the file.

Exploitation yields code execution in the browser context of the viewing user. An attacker can steal authentication cookies, perform actions through the WordPress REST API on behalf of an administrator, create new privileged users, or install a backdoor plugin.

Root Cause

The plugin omits server-side sanitization of SVG file contents before writing the file to the uploads directory. XML nodes such as <script>, <foreignObject>, and attributes prefixed with on are preserved as-is. This maps to CWE-79 (Improper Neutralization of Input During Web Page Generation) combined with CWE-434 (Unrestricted Upload of File with Dangerous Type).

Attack Vector

Exploitation requires an authenticated session with Author privileges or higher and a subsequent view action by a targeted user. The attacker uploads an SVG containing a script payload through the plugin's media handler. When any WordPress user opens the media item directly or via a page that embeds it, the browser parses the SVG and executes the embedded JavaScript against the site origin.

No verified public exploit code is available. Refer to the WPScan Vulnerability Details advisory for additional technical context.

Detection Methods for CVE-2025-9698

Indicators of Compromise

  • SVG files in wp-content/uploads/ containing <script> elements, javascript: URIs, or on* event handler attributes
  • New administrator accounts created shortly after an Author account uploaded media
  • Unexpected plugin installations or theme file modifications following media library activity
  • Outbound requests from administrator browsers to unfamiliar domains after viewing plugin-managed media

Detection Strategies

  • Scan the uploads directory for SVG files and inspect XML content for scriptable elements or event handlers
  • Audit WordPress user metadata for role escalations and new user creation events correlated to Author sessions
  • Review web server access logs for SVG requests followed by administrative REST API calls from the same session
  • Query the installed version of The Plus Addons for Elementor and flag any instance below 6.3.16

Monitoring Recommendations

  • Alert on SVG file uploads by non-administrator accounts and route them to manual review
  • Monitor changes to wp_users and wp_usermeta tables, especially assignment of administrator capabilities
  • Track outbound HTTP requests from browsers with active WordPress admin sessions to detect data exfiltration

How to Mitigate CVE-2025-9698

Immediate Actions Required

  • Update The Plus Addons for Elementor to version 6.3.16 or later on all WordPress installations
  • Audit existing SVG files in the media library and remove any containing script or event-handler content
  • Review Author and higher accounts for unauthorized creation, and reset credentials for suspicious users
  • Rotate WordPress administrator sessions and secret keys defined in wp-config.php if compromise is suspected

Patch Information

The vendor addressed the issue in The Plus Addons for Elementor version 6.3.16 by sanitizing SVG file contents on upload. Site operators should apply the update through the WordPress plugin manager or by replacing the plugin directory with the patched release. See the WPScan Vulnerability Details for advisory metadata.

Workarounds

  • Disable SVG uploads entirely by removing image/svg+xml from allowed MIME types until patching is complete
  • Restrict the Author role from uploading files by adjusting capabilities with a role manager plugin
  • Serve wp-content/uploads/ with a Content-Security-Policy that blocks inline scripts and script execution from that path
  • Place the site behind a Web Application Firewall rule that inspects SVG uploads for <script> tags and on* attributes
bash
# Configuration example: block SVG execution via nginx for the uploads directory
location ~* ^/wp-content/uploads/.*\.svg$ {
    add_header Content-Security-Policy "script-src 'none'; object-src 'none'";
    add_header X-Content-Type-Options "nosniff";
    types { image/svg+xml svg; }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.