brainstormforce Vulnerabilities and Affected Products
Vulnerabilities associated with Ultimate Addons for Elementor.
Products
Clear product- Spectra Gutenberg Blocks – Website Builder for the Block Editor11 vulnerabilities
- Ultimate Addons for Elementor10 vulnerabilities
- SureForms – Contact Form, Payment Form & Other Custom Form Builder7 vulnerabilities
- Ultimate Addons for Beaver Builder – Lite5 vulnerabilities
- CartFlows – Funnel Builder & Checkout Plugin for WooCommerce3 vulnerabilities
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg3 vulnerabilities
- ultimate_addons_for_elementor3 vulnerabilities
- Astra2 vulnerabilities
- Custom Fonts – Host Your Fonts Locally2 vulnerabilities
- OttoKit: All-in-One Automation Platform2 vulnerabilities
- spectra2 vulnerabilities
- SureForms – Drag and Drop Form Builder for WordPress2 vulnerabilities
- convertplug1 vulnerability
- Import / Export Customizer Settings1 vulnerability
- Lightweight Sidebar Manager1 vulnerability
- Spectra Legacy – Gutenberg Blocks1 vulnerability
- spectra_pro1 vulnerability
- Starter Templates — Elementor, Gutenberg & Beaver Builder Templates1 vulnerability
- starter_templates1 vulnerability
- Surecart1 vulnerability
- SureDash – Community, Courses & Member Dashboard1 vulnerability
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz1 vulnerability
- SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator1 vulnerability
- SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers1 vulnerability
- ultimate_addons_for_wpbakery_page_builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15787MEDIUM | Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon AttributesThe Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save … CWE-79Jul 22, 2026 | CVSS6.4v3.1 | EPSS0.241% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8488MEDIUM | Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings UpdateThe Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting. CWE-862Aug 2, 2025 | CVSS4.3v3.1 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-11230MEDIUM | Elementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title WidgetThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Dec 23, 2024 | CVSS6.4v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10325MEDIUM | Elementor Header & Footer Builder <= 1.6.45 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CWE-79Nov 8, 2024 | CVSS6.4v3.1 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10050MEDIUM | Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via ShortcodeThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own. CWE-200Oct 24, 2024 | CVSS4.3v3.1 | EPSS0.484% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5757MEDIUM | Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title WidgetThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jun 13, 2024 | CVSS6.4v3.1 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2618MEDIUM | Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site ScriptingThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS6.4v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2619MEDIUM | Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Author+) HTML InjectionThe Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page. | CVSS5.0v3.1 | EPSS0.377% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4634MEDIUM | Elementor Header & Footer Builder <= 1.6.28 - Authenticated (Contributor+) Stored Cross-Site ScriptingThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79May 16, 2024 | CVSS6.4v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1237MEDIUM | Elementor Header & Footer Builder <= 1.6.24 - Authenticated (Contributor+) Stored Cross-Site ScriptingThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 13, 2024 | CVSS6.4v3.1 | EPSS0.514% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |