← WordPress Vulnerabilities
WordPress security by component

Ultimate Addons for Elementor

Ultimate Addons for Elementor is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 22, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: header-footer-elementor

CVE-2026-15787: Ultimate Addons navigation icons allow contributor stored XSS

Ultimate Addons for Elementor 2.9.1 and earlier does not safely handle the Navigation Menu widget's data-toggle-icon and data-close-icon attributes. A contributor can store an HTML-entity-encoded payload that survives WordPress sanitization, is decoded by the browser, and is inserted as markup by jQuery when a visitor opens the affected page.

PublishedJul 22, 2026
Known safe version2.9.2
Safe version
Jul 22, 2026 CVE-2026-15787
Ultimate Addons navigation icons allow contributor stored XSS
Ultimate Addons for Elementor 2.9.1 and earlier does not safely handle the Navigation Menu widget's data-toggle-icon and data-close-icon attributes. A contributor can store an HTML-entity-encoded payload that survives WordPress sanitization, is decoded by the browser, and is inserted as markup by jQuery when a visitor opens the affected page.
2.9.2
CVE6.4
NVDPending
Aug 02, 2025 CVE-2025-8488
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder): A security weakness
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 23, 2024 CVE-2024-11230
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 08, 2024 CVE-2024-10325
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 24, 2024 CVE-2024-10050
Elementor Header & Footer Builder: Sensitive information exposure
Elementor Header & Footer Builder is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jul 22, 2024 CVE-2024-33933
Elementor – Header, Footer & Blocks Template: Cross-site scripting
Elementor – Header, Footer & Blocks Template is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 13, 2024 CVE-2024-5757
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 24, 2024 CVE-2024-2618
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 16, 2024 CVE-2024-2619
Header Footer Elementor: A security weakness
Header Footer Elementor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.4
May 16, 2024 CVE-2024-4634
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1237
Elementor Header & Footer Builder: Cross-site scripting
Elementor Header & Footer Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4