CVE-2026-66688
- EPSS 0.14%
- Veröffentlicht 06.08.2026 14:28:00
- Zuletzt bearbeitet 12.08.2026 20:59:00
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-15787
- EPSS 0.24%
- Veröffentlicht 22.07.2026 09:16:27
- Zuletzt bearbeitet 22.07.2026 19:16:55
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitizat...
CVE-2025-8488
- EPSS 0.23%
- Veröffentlicht 02.08.2025 09:23:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all v...
CVE-2024-37455
- EPSS 0.48%
- Veröffentlicht 09.07.2024 11:15:15
- Zuletzt bearbeitet 21.11.2024 09:23:52
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
CVE-2023-50890
- EPSS 0.55%
- Veröffentlicht 17.05.2024 09:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.
CVE-2021-24271
- EPSS 0.59%
- Veröffentlicht 05.05.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:43
The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
CVE-2020-13125
- EPSS 2.31%
- Veröffentlicht 17.05.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:42
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if re...