plugin

Header Footer Elementor Vulnerabilities

26 known security issues reported for the Header Footer Elementor WordPress plugin. Most recent disclosed Jul 21, 2026.

13 medium

Running Header Footer Elementor on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

medium

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Jul 21, 2026

CVE-2026-15787 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 2.5.0

unknown

[en] A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Oct 3, 2025

CVE-2025-60448 on NVD →

Ultimate Addons for Elementor Lite <= 2.4.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

medium

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Sep 15, 2025

CVE-2025-9703 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update

medium

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authen...

CVSS:
4.3
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Aug 1, 2025

CVE-2025-8488 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.47

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

Affected:
up to 1.6.47
Fixed in:
1.6.47
Disclosed:
Dec 23, 2024

CVE-2024-11230 on NVD →

Elementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and...

CVSS:
6.4
Affected:
up to 1.6.46
Fixed in:
1.6.47
Disclosed:
Dec 22, 2024

CVE-2024-11230 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.46

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access...

Affected:
up to 1.6.46
Fixed in:
1.6.46
Disclosed:
Nov 8, 2024

CVE-2024-10325 on NVD →

Elementor Header & Footer Builder <= 1.6.45 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and...

CVSS:
6.4
Affected:
up to 1.6.45
Fixed in:
1.6.46
Disclosed:
Nov 7, 2024

CVE-2024-10325 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.44

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Pas...

Affected:
up to 1.6.44
Fixed in:
1.6.44
Disclosed:
Oct 24, 2024

CVE-2024-10050 on NVD →

Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password...

CVSS:
4.3
Affected:
up to 1.6.43
Fixed in:
1.6.44
Disclosed:
Oct 23, 2024

CVE-2024-10050 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.36

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor – Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor – Header, Footer & Blocks Template: from n/a through 1.6.35.

Affected:
up to 1.6.36
Fixed in:
1.6.36
Disclosed:
Jul 22, 2024

CVE-2024-33933 on NVD →

Elementor – Header, Footer & Blocks Template <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor – Header, Footer & Blocks Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...

CVSS:
6.4
Affected:
up to 1.6.35
Fixed in:
1.6.36
Disclosed:
Jul 1, 2024

CVE-2024-33933 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.36

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 1.6.36
Fixed in:
1.6.36
Disclosed:
Jun 13, 2024

CVE-2024-5757 on NVD →

Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 1.6.35
Fixed in:
1.6.36
Disclosed:
Jun 12, 2024

CVE-2024-5757 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.26.1

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or high...

Affected:
up to 1.6.26.1
Fixed in:
1.6.26.1
Disclosed:
May 24, 2024

CVE-2024-2618 on NVD →

Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, t...

CVSS:
6.4
Affected:
up to 1.6.26
Fixed in:
1.6.26.1
Disclosed:
May 23, 2024

CVE-2024-2618 on NVD →

Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Author+) HTML Injection

medium

The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that...

CVSS:
5
Affected:
up to 1.6.26
Fixed in:
1.6.27
Disclosed:
May 16, 2024

CVE-2024-2619 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.27

unknown

[en] The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages...

Affected:
up to 1.6.27
Fixed in:
1.6.27
Disclosed:
May 16, 2024

CVE-2024-2619 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.29

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...

Affected:
up to 1.6.29
Fixed in:
1.6.29
Disclosed:
May 16, 2024

CVE-2024-4634 on NVD →

Elementor Header & Footer Builder <= 1.6.28 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level pe...

CVSS:
6.4
Affected:
up to 1.6.28
Fixed in:
1.6.29
Disclosed:
May 15, 2024

CVE-2024-4634 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.6.25

unknown

[en] The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor acces...

Affected:
up to 1.6.25
Fixed in:
1.6.25
Disclosed:
Mar 13, 2024

CVE-2024-1237 on NVD →

Elementor Header & Footer Builder <= 1.6.24 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and...

CVSS:
6.4
Affected:
up to 1.6.24
Fixed in:
1.6.25
Disclosed:
Mar 11, 2024

CVE-2024-1237 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.5.8

unknown

[en] The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
May 5, 2021

CVE-2021-24256 on NVD →

Elementor Header & Footer Builder <= 1.5.7 - Stored Cross-Site Scripting

medium

The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
6.4
Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Apr 13, 2021

CVE-2021-24256 on NVD →

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 1.5.8

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Elementor – Header, Footer & Blocks Template plugin (versions <= 1.5.7).

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Apr 13, 2021

Ultimate Addons for Elementor (Formerly Elementor Header &amp; Footer Builder) [header-footer-elementor] < 2.4.7

unknown
Affected:
up to 2.4.7
Fixed in:
2.4.7

CVE-2025-8488 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database