Elementor Header Footer Builder Brainstormforce Elementor Header Footer Builder

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Elementor Header Footer Builder.

By the Year

In 2026 there have been 0 vulnerabilities in Brainstormforce Elementor Header Footer Builder. Last year, in 2025 Elementor Header Footer Builder had 1 security vulnerability published. Right now, Elementor Header Footer Builder is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 1 4.30
2024 7 5.90

It may take a day or so for new Elementor Header Footer Builder vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Elementor Header Footer Builder Security Vulnerabilities

Auth Data Mod via missing cap check before v2.4.6 – Ultimate Addons
CVE-2025-8488 4.3 - Medium - August 02, 2025

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

AuthZ

Elementor Header & Footer Builder Plugin: Stored XSS via Size Parameter
CVE-2024-11230 6.4 - Medium - December 23, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Elementor Header & Footer XSS via SVG Upload
CVE-2024-10325 6.4 - Medium - November 08, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

XSS

Elementor HFE Shortcode Info Disclosure 1.6.43
CVE-2024-10050 4.3 - Medium - October 24, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.

Information Disclosure

Elementor H&F Builder 1.6.26: Stored XSS via size attribute
CVE-2024-2618 6.4 - Medium - May 24, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Improper Neutralization of Alternate XSS Syntax

Elementor Header/Footer Builder <=1.6.26 Authenticated HTML Injection
CVE-2024-2619 5 - Medium - May 16, 2024

The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.

AuthZ

WP Elementor H&F Builder 1.6.28 Stored XSS via hfe_svg_mime_types
CVE-2024-4634 6.4 - Medium - May 16, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hfe_svg_mime_types function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

WordPress Elementor Header & Footer Builder XSS via flyout_layout (1.6.24)
CVE-2024-1237 6.4 - Medium - March 13, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Elementor Header Footer Builder or by Brainstormforce? Click the Watch button to subscribe.

subscribe