PLUGIN SECURITY

Is Ultimate Addons for Elementor (UAE) safe?

Elementor addons with 18+ free widgets, Header & Footer Builder, WooCommerce widgets & templates. Trusted by 2+ million websites.

What this plugin does

  • Slug: header-footer-elementor
  • Author: Brainstorm Force
  • 2000000+ active installs
  • 98/100 rating (2525 reviews on wordpress.org)
  • 69551037 all-time downloads
  • On WordPress.org since 2017-03-07

elementorelementor addonselementor templateselementor widgetsheader footer builder

Maintenance status

  • Latest known version: 2.9.2
  • Last updated: 2026-08-26 8:03am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

14 known CVEs on file for Ultimate Addons for Elementor (UAE).

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-60448 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 2.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.0 2.5.0 2025-10-03 ✓ fixed in latest
CVE-2024-11230 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.47 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.6.47 1.6.47 2024-12-22 ✓ fixed in latest
CVE-2024-10325 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.46 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.6.46 1.6.46 2024-11-07 ✓ fixed in latest
CVE-2024-10050 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.44 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 1.6.44 1.6.44 2024-10-23 ✓ fixed in latest
CVE-2024-33933 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.36 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.36 1.6.36 2024-07-01 ✓ fixed in latest
CVE-2024-5757 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.36 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.36 1.6.36 2024-06-12 ✓ fixed in latest
CVE-2024-2618 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.26.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.26.1 1.6.26.1 2024-05-23 ✓ fixed in latest
CVE-2024-2619 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.27 1.6.27 2024-05-16 ✓ fixed in latest
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4634 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.29 1.6.29 2024-05-15 ✓ fixed in latest
CVE-2024-1237 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.6.25 1.6.25 2024-03-11 ✓ fixed in latest
CVE-2021-24256 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.8 1.5.8 2021-04-13 ✓ fixed in latest
Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.5.8 Unknown < 1.5.8 1.5.8 2021-04-13 ✓ fixed in latest
Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 2.4.7 Missing Authorization Medium 4.3 < 2.4.7 2.4.7 0000-00-00 ✓ fixed in latest
Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 2.5.0 Unknown < 2.5.0 2.5.0 0000-00-00 ✓ fixed in latest
Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 2.9.2 Unknown < 2.9.2 2.9.2 0000-00-00 ✓ fixed in latest
CVE-2025-8488 Ultimate Addons for Elementor < 2.4.7 - Subscriber+ Limited Settings Update Unknown < 2.4.7 2.4.7 ✓ fixed in latest
CVE-2025-9703 Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS Unknown < 2.5.0 2.5.0 ✓ fixed in latest
CVE-2026-15787 Ultimate Addons for Elementor < 2.9.2 - Contributor+ Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes Unknown < 2.9.2 2.9.2 ✓ fixed in latest

How to fix it

Keep Ultimate Addons for Elementor (UAE) updated — 2.9.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.