CVE-2025-14149: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14149 is a Stored Cross-Site Scripting (XSS) vulnerability in the Xpro Addons — 140+ Widgets for Elementor plugin for WordPress. It affects all versions up to and including 1.4.24, stemming from insufficient input sanitization and output escaping on the Image Scroller widget's box link attribute. Authenticated attackers with contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. The vulnerability was published on February 27, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability exists in the Image Scroller widget's frontend rendering code (widgets/image-scroller/layout/frontend.php), where the box link attribute accepts user-supplied input that is neither properly sanitized on input nor escaped on output. An authenticated contributor can craft a malicious link attribute value containing JavaScript, which is then stored in the database and rendered unsanitized to all subsequent page visitors. The fix was introduced in the plugin's changeset 3470049 (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected Image Scroller widget. This can lead to session cookie theft, credential harvesting, defacement of page content, redirection to malicious sites, or delivery of further malware payloads to site visitors. While the CVSS scope is changed (affecting users beyond the attacker's session), the confidentiality and integrity impacts are rated low and availability is unaffected (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14149. The EPSS score is approximately 0.029%, indicating a low probability of exploitation in the near term. The vulnerability requires authenticated access at contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Xpro Addons — 140+ Widgets for Elementor plugin at version 1.4.24 or earlier, using tools like WPScan or by inspecting plugin metadata in page source.
  2. Obtain contributor access: Register or compromise an account with at least contributor-level privileges on the target WordPress site.
  3. Create or edit a page/post: Navigate to the WordPress editor and add or edit a page that includes the Image Scroller widget from the Xpro Addons plugin.
  4. Inject malicious payload: In the Image Scroller widget's box link attribute field, insert a JavaScript payload such as javascript:/*--></title></style></textarea></script><script>alert(document.cookie)</script> or a more targeted payload for session hijacking.
  5. Publish the page: Save and publish the page, causing the malicious script to be stored in the WordPress database.
  6. Trigger execution: When any site visitor (including administrators) loads the injected page, the stored script executes in their browser, enabling cookie theft, credential harvesting, or further attacks (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or REST API endpoints by contributor-level accounts adding or editing pages with Image Scroller widget content containing javascript: URI schemes or encoded script tags.
  • Database: Suspicious entries in the wp_posts or wp_postmeta tables where the Image Scroller widget's box link attribute contains <script>, javascript:, or encoded XSS payloads.
  • Network: Outbound requests from victim browsers to attacker-controlled domains (e.g., for cookie exfiltration) originating from pages hosting the Image Scroller widget.
  • File System: Unexpected modifications to wp-content/plugins/xpro-elementor-addons/widgets/image-scroller/layout/frontend.php if an attacker has also achieved file write access (Wordfence).

Mitigation and workarounds

Update the Xpro Addons — 140+ Widgets for Elementor plugin to version 1.4.25 or later, which includes the fix applied in changeset 3470049 that adds proper output escaping to the Image Scroller widget's box link attribute. As a temporary workaround, restrict contributor-level user registrations or disable the Image Scroller widget until the update can be applied. Site administrators should also audit existing pages for any previously injected malicious content in Image Scroller widgets (Wordfence, WordPress Trac).

Community reactions

The vulnerability was discovered and disclosed by Wordfence, which assigned the CVE and published the advisory. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant media coverage identified beyond standard CVE tracking (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management