N/A
2025-09-15< 2.5.0
Ultimate Addons for Elementor Lite <= 2.4.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
Minimum safe version
2.5.0
Update to 2.5.0 or later to address 14 fixable vulnerabilities
Ultimate Addons for Elementor Lite <= 2.4.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
CVE-2025-60448
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
CVE-2024-11230
CVE-2024-10325
CVE-2024-10050
CVE-2024-33933
CVE-2024-5757
CVE-2024-2618
CVE-2024-2619
CVE-2024-4634
CVE-2024-1237
WordPress Elementor – Header, Footer & Blocks Template plugin <= 1.5.7 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24256