Brainstormforce Ultimate Addons For Elementor
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Brainstormforce Ultimate Addons For Elementor.
By the Year
In 2026 there have been 1 vulnerability in Brainstormforce Ultimate Addons For Elementor with an average score of 6.4 out of ten. Ultimate Addons For Elementor did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.40 |
| 2025 | 0 | 0.00 |
| 2024 | 9 | 6.28 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 5.40 |
| 2020 | 1 | 6.50 |
It may take a day or so for new Ultimate Addons For Elementor vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Ultimate Addons For Elementor Security Vulnerabilities
XSS in Ultimate Addons for Elementor Nav Menu Widget (<=2.9.1)
CVE-2026-15787
6.4 - Medium
- July 22, 2026
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.
XSS
Elementor Header & Footer Builder Plugin: Stored XSS via Size Parameter
CVE-2024-11230
6.4 - Medium
- December 23, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Elementor Header & Footer XSS via SVG Upload
CVE-2024-10325
6.4 - Medium
- November 08, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
XSS
Elementor HFE Shortcode Info Disclosure 1.6.43
CVE-2024-10050
4.3 - Medium
- October 24, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
Information Disclosure
Privilege Escalation in Ultimate Addons for Elementor 1.36.31
CVE-2024-37455
8.8 - High
- July 09, 2024
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
Improper Privilege Management
Elementor Header & Footer Builder <=1.6.35 XSS via URL in Site Title widget
CVE-2024-5757
6.4 - Medium
- June 13, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Elementor H&F Builder 1.6.26: Stored XSS via size attribute
CVE-2024-2618
6.4 - Medium
- May 24, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Improper Neutralization of Alternate XSS Syntax
Elementor Header/Footer Builder <=1.6.26 Authenticated HTML Injection
CVE-2024-2619
5 - Medium
- May 16, 2024
The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.
AuthZ
WP Elementor H&F Builder 1.6.28 Stored XSS via hfe_svg_mime_types
CVE-2024-4634
6.4 - Medium
- May 16, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hfe_svg_mime_types function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
WordPress Elementor Header & Footer Builder XSS via flyout_layout (1.6.24)
CVE-2024-1237
6.4 - Medium
- March 13, 2024
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets
CVE-2021-24271
5.4 - Medium
- May 05, 2021
The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
XSS
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress
CVE-2020-13125
6.5 - Medium
- May 17, 2020
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Incorrect Permission Assignment for Critical Resource
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Brainstormforce Ultimate Addons For Elementor or by Brainstormforce? Click the Watch button to subscribe.