Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ultimate Addons for Elementor — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Ultimate Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Ultimate Addons for Elementor, a popular plugin for the WordPress page builder ecosystem. The collection encompasses various weakness types, including Cross-Site Scripting, Cross-Site Request Forgery, and SQL Injection, covering advisories published over the last five years. Users can leverage this data to track the vendor’s response patterns to emerging threats, analyze the prevalence of specific weakness classes within the plugin, or review the comprehensive vulnerability history to assess the overall security posture of the product. By centralizing this information, the page provides a clear, factual overview of past incidents without subjective commentary. It serves as a reference for security professionals, developers, and site administrators who need to understand potential risks associated with this extension. The data is organized to facilitate trend analysis and rapid identification of recurring issue categories, enabling stakeholders to make informed decisions regarding patch management and mitigation strategies. This resource focuses strictly on documented flaws and their remediation status, offering a transparent look at the security lifecycle of the addon. It does not include speculative threats or unverified reports, ensuring that all listed items are based on confirmed disclosures. Whether you are auditing a website’s plugin stack or researching common vulnerabilities in WordPress extensions, this aggregation provides the necessary context to understand the specific security challenges faced by Ultimate Addons for Elementor users.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-66688 WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-08-06
CVE-2026-15787 Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes CWE-79 6.4 Medium 2026-07-22
CVE-2025-8488 Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update CWE-862 4.3 Medium 2025-08-02
CVE-2024-11230 Elementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget CWE-79 6.4 Medium 2024-12-23
CVE-2024-10325 Elementor Header & Footer Builder <= 1.6.45 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium 2024-11-08
CVE-2024-10050 Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode CWE-200 4.3 Medium 2024-10-24
CVE-2024-37455 WordPress Ultimate Addons for elementor plugin <= 1.36.31 - Privilege Escalation vulnerability CWE-269 8.8 High 2024-07-09
CVE-2024-5757 Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget CWE-79 6.4 Medium 2024-06-13
CVE-2024-2618 Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-87 6.4 Medium 2024-05-24
CVE-2023-50890 WordPress Ultimate Addons for Elementor plugin <= 1.36.20 - Privilege Escalation vulnerability CWE-269 8.8 High 2024-05-17
CVE-2024-2619 Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Author+) HTML Injection CWE-862 5.0 Medium 2024-05-16
CVE-2024-4634 Elementor Header & Footer Builder <= 1.6.28 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-05-16
CVE-2024-1237 Elementor Header & Footer Builder <= 1.6.24 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-03-13
CVE-2021-24271 Ultimate Addons for Elementor < 1.30.0 - Contributor+ Stored XSS CWE-79 5.4 - 2021-05-05

All 14 known CVE vulnerabilities affecting Ultimate Addons for Elementor with full Chinese analysis, references, and POCs where available.