
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14149 is a Stored Cross-Site Scripting (XSS) vulnerability in the Xpro Addons — 140+ Widgets for Elementor plugin for WordPress. It affects all versions up to and including 1.4.24, stemming from insufficient input sanitization and output escaping on the Image Scroller widget's box link attribute. Authenticated attackers with contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. The vulnerability was published on February 27, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability exists in the Image Scroller widget's frontend rendering code (widgets/image-scroller/layout/frontend.php), where the box link attribute accepts user-supplied input that is neither properly sanitized on input nor escaped on output. An authenticated contributor can craft a malicious link attribute value containing JavaScript, which is then stored in the database and rendered unsanitized to all subsequent page visitors. The fix was introduced in the plugin's changeset 3470049 (Wordfence, WordPress Trac).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected Image Scroller widget. This can lead to session cookie theft, credential harvesting, defacement of page content, redirection to malicious sites, or delivery of further malware payloads to site visitors. While the CVSS scope is changed (affecting users beyond the attacker's session), the confidentiality and integrity impacts are rated low and availability is unaffected (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14149. The EPSS score is approximately 0.029%, indicating a low probability of exploitation in the near term. The vulnerability requires authenticated access at contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
javascript:/*--></title></style></textarea></script><script>alert(document.cookie)</script> or a more targeted payload for session hijacking.wp-admin/post.php or REST API endpoints by contributor-level accounts adding or editing pages with Image Scroller widget content containing javascript: URI schemes or encoded script tags.wp_posts or wp_postmeta tables where the Image Scroller widget's box link attribute contains <script>, javascript:, or encoded XSS payloads.wp-content/plugins/xpro-elementor-addons/widgets/image-scroller/layout/frontend.php if an attacker has also achieved file write access (Wordfence).Update the Xpro Addons — 140+ Widgets for Elementor plugin to version 1.4.25 or later, which includes the fix applied in changeset 3470049 that adds proper output escaping to the Image Scroller widget's box link attribute. As a temporary workaround, restrict contributor-level user registrations or disable the Image Scroller widget until the update can be applied. Site administrators should also audit existing pages for any previously injected malicious content in Image Scroller widgets (Wordfence, WordPress Trac).
The vulnerability was discovered and disclosed by Wordfence, which assigned the CVE and published the advisory. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant media coverage identified beyond standard CVE tracking (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."