CVE-2025-9698 Overview
CVE-2025-9698 is a Stored Cross-Site Scripting (XSS) vulnerability in The Plus Addons for Elementor WordPress plugin. Versions prior to 6.3.16 fail to sanitize the contents of uploaded SVG files. An authenticated user with Author-level access or higher can upload a crafted SVG that executes arbitrary JavaScript when rendered in a victim's browser.
The flaw enables session hijacking, credential theft, and administrative account takeover when a higher-privileged user views the malicious media. Because Author is a low-trust role on many WordPress sites that accept contributor content, the barrier to exploitation is limited to obtaining or compromising a single content-producing account.
Critical Impact
An authenticated Author can plant persistent JavaScript in an SVG that executes against administrators, leading to full site compromise.
Affected Products
- The Plus Addons for Elementor WordPress plugin, all versions before 6.3.16
- WordPress sites permitting SVG uploads through the plugin
- Sites where Author-level or higher accounts exist and can be provisioned or compromised
Discovery Timeline
- 2025-10-13 - CVE-2025-9698 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9698
Vulnerability Analysis
The vulnerability is a Stored Cross-Site Scripting weakness triggered through unsanitized Scalable Vector Graphics (SVG) file uploads. SVG is an XML-based image format that natively supports <script> elements and event handlers such as onload and onclick. When a web application accepts SVG files without stripping executable content, any embedded JavaScript runs in the origin of the hosting site.
The Plus Addons for Elementor accepts SVG uploads from users with Author role or above but does not pass file contents through a sanitizer such as enshrined/svg-sanitize. The malicious payload persists in the WordPress media library and executes whenever an authenticated user, including an administrator, opens or previews the file.
Exploitation yields code execution in the browser context of the viewing user. An attacker can steal authentication cookies, perform actions through the WordPress REST API on behalf of an administrator, create new privileged users, or install a backdoor plugin.
Root Cause
The plugin omits server-side sanitization of SVG file contents before writing the file to the uploads directory. XML nodes such as <script>, <foreignObject>, and attributes prefixed with on are preserved as-is. This maps to CWE-79 (Improper Neutralization of Input During Web Page Generation) combined with CWE-434 (Unrestricted Upload of File with Dangerous Type).
Attack Vector
Exploitation requires an authenticated session with Author privileges or higher and a subsequent view action by a targeted user. The attacker uploads an SVG containing a script payload through the plugin's media handler. When any WordPress user opens the media item directly or via a page that embeds it, the browser parses the SVG and executes the embedded JavaScript against the site origin.
No verified public exploit code is available. Refer to the WPScan Vulnerability Details advisory for additional technical context.
Detection Methods for CVE-2025-9698
Indicators of Compromise
- SVG files in wp-content/uploads/ containing <script> elements, javascript: URIs, or on* event handler attributes
- New administrator accounts created shortly after an Author account uploaded media
- Unexpected plugin installations or theme file modifications following media library activity
- Outbound requests from administrator browsers to unfamiliar domains after viewing plugin-managed media
Detection Strategies
- Scan the uploads directory for SVG files and inspect XML content for scriptable elements or event handlers
- Audit WordPress user metadata for role escalations and new user creation events correlated to Author sessions
- Review web server access logs for SVG requests followed by administrative REST API calls from the same session
- Query the installed version of The Plus Addons for Elementor and flag any instance below 6.3.16
Monitoring Recommendations
- Alert on SVG file uploads by non-administrator accounts and route them to manual review
- Monitor changes to wp_users and wp_usermeta tables, especially assignment of administrator capabilities
- Track outbound HTTP requests from browsers with active WordPress admin sessions to detect data exfiltration
How to Mitigate CVE-2025-9698
Immediate Actions Required
- Update The Plus Addons for Elementor to version 6.3.16 or later on all WordPress installations
- Audit existing SVG files in the media library and remove any containing script or event-handler content
- Review Author and higher accounts for unauthorized creation, and reset credentials for suspicious users
- Rotate WordPress administrator sessions and secret keys defined in wp-config.php if compromise is suspected
Patch Information
The vendor addressed the issue in The Plus Addons for Elementor version 6.3.16 by sanitizing SVG file contents on upload. Site operators should apply the update through the WordPress plugin manager or by replacing the plugin directory with the patched release. See the WPScan Vulnerability Details for advisory metadata.
Workarounds
- Disable SVG uploads entirely by removing image/svg+xml from allowed MIME types until patching is complete
- Restrict the Author role from uploading files by adjusting capabilities with a role manager plugin
- Serve wp-content/uploads/ with a Content-Security-Policy that blocks inline scripts and script execution from that path
- Place the site behind a Web Application Firewall rule that inspects SVG uploads for <script> tags and on* attributes
# Configuration example: block SVG execution via nginx for the uploads directory
location ~* ^/wp-content/uploads/.*\.svg$ {
add_header Content-Security-Policy "script-src 'none'; object-src 'none'";
add_header X-Content-Type-Options "nosniff";
types { image/svg+xml svg; }
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
