CVE Details
Basic Information
| Title | Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update |
|---|---|
| Type | cve |
| Published | 2025-08-02T09:23:31.864Z |
| Modified | 2025-08-02T09:23:31.864Z |
Product Information
| Vendor | brainstormforce |
|---|---|
| Product | Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) |
| Version | * |
CVSS Information
| Base Score | 4.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
AI Analysis
| AI Description | The Ultimate Addons for Elementor plugin is vulnerable due to a missing capability check, allowing authenticated users with Subscriber access or higher to modify settings. This could lead to unauthorized changes in the plugin’s configuration. |
|---|---|
| AI Severity | Medium |
| AI Vendor | brainstormforce |
| AI Product | Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) |
| AI Version | 2.4.6 |
Affected Products
- brainstormforce Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) *
Additional Information
| CWE List | CWE-862 |
|---|---|
| Source | Wordfence |
Description
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback() function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b847b5-9deb-41c4-b976-725249e0098e?source=cve
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.4.6/admin/class-hfe-addons-actions.php#L494
- https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.4.7/admin/class-hfe-addons-actions.php#L525