Ultimate Addons For Elementor Brainstormforce Ultimate Addons For Elementor

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Ultimate Addons For Elementor.

By the Year

In 2026 there have been 1 vulnerability in Brainstormforce Ultimate Addons For Elementor with an average score of 6.4 out of ten. Ultimate Addons For Elementor did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 1 6.40
2025 0 0.00
2024 9 6.28
2023 0 0.00
2022 0 0.00
2021 1 5.40
2020 1 6.50

It may take a day or so for new Ultimate Addons For Elementor vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Ultimate Addons For Elementor Security Vulnerabilities

XSS in Ultimate Addons for Elementor Nav Menu Widget (<=2.9.1)
CVE-2026-15787 6.4 - Medium - July 22, 2026

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.

XSS

Elementor Header & Footer Builder Plugin: Stored XSS via Size Parameter
CVE-2024-11230 6.4 - Medium - December 23, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Elementor Header & Footer XSS via SVG Upload
CVE-2024-10325 6.4 - Medium - November 08, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

XSS

Elementor HFE Shortcode Info Disclosure 1.6.43
CVE-2024-10050 4.3 - Medium - October 24, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.

Information Disclosure

Privilege Escalation in Ultimate Addons for Elementor 1.36.31
CVE-2024-37455 8.8 - High - July 09, 2024

Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.

Improper Privilege Management

Elementor Header & Footer Builder <=1.6.35 XSS via URL in Site Title widget
CVE-2024-5757 6.4 - Medium - June 13, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Elementor H&F Builder 1.6.26: Stored XSS via size attribute
CVE-2024-2618 6.4 - Medium - May 24, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Improper Neutralization of Alternate XSS Syntax

Elementor Header/Footer Builder <=1.6.26 Authenticated HTML Injection
CVE-2024-2619 5 - Medium - May 16, 2024

The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.

AuthZ

WP Elementor H&F Builder 1.6.28 Stored XSS via hfe_svg_mime_types
CVE-2024-4634 6.4 - Medium - May 16, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hfe_svg_mime_types function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

WordPress Elementor Header & Footer Builder XSS via flyout_layout (1.6.24)
CVE-2024-1237 6.4 - Medium - March 13, 2024

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets
CVE-2021-24271 5.4 - Medium - May 05, 2021

The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

XSS

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress
CVE-2020-13125 6.5 - Medium - May 17, 2020

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

Incorrect Permission Assignment for Critical Resource

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Ultimate Addons For Elementor or by Brainstormforce? Click the Watch button to subscribe.

subscribe