{"error":0,"message":null,"data":{"name":"Ultimate Addons for Elementor","plugin":"ultimate-elementor","link":"https:\/\/ultimateelementor.com\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"87a22063c834ed5b0854cf2ebb35564f599853bae89184d90eefa9e9b28a7512","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.30.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.30.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24271","name":"CVE-2021-24271","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24271","description":"[en] The \u201cUltimate Addons for Elementor\u201d WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.","date":"2021-05-05"},{"id":"1ce8e188-6ded-413e-b4d1-bf80258acf79","name":"Ultimate Addons for Elementor &lt; 1.30.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/1ce8e188-6ded-413e-b4d1-bf80258acf79","description":"The &ldquo;Ultimate Addons for Elementor&rdquo; WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.\r\n\r\nThese vulnerabilities were discovered and patched by Brainstorm Force after the Wordfence Threat Intelligence team notified them of similar vulnerabilities in their &quot; Elementor &ndash; Header, Footer &amp; Blocks Template&quot; plugin, and are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https:\/\/www.wordfence.com\/blog\/2021\/03\/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites\/","date":null},{"id":"b575f521fdd667072066b2c65d021ed159d1dc88","name":"Ultimate Addons for Elementor < 1.30.0 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-elementor\/ultimate-addons-for-elementor-1300-stored-cross-site-scripting","description":"The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.","date":"2021-04-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"52dad2d520fcb6aec2da7b536f7d16a2f2533b0ba13d1dea2f0bcc85787e3c33","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.30.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.30.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52ba41f942d6d505bad96b6b2bc8b410f86b92c8","name":"WordPress Ultimate Addons for Elementor premium plugin <= 1.29.2 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-elementor\/vulnerability\/wordpress-ultimate-addons-for-elementor-plugin-1-29-2-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Ultimate Addons for Elementor premium plugin (versions <= 1.29.2).","date":"2021-04-13"}],"impact":[]},{"uuid":"beaab207b53bcf866263d0024531a16998d3e7392e7e609f3baaf554c0c7897e","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.24.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.24.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-13125","name":"CVE-2020-13125","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-13125","description":"[en] An issue was discovered in the \"Ultimate Addons for Elementor\" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.","date":"2020-05-17"},{"id":"34f1d35679fcd5a6c1a2954f833411f2bd6e9797","name":"WordPress Ultimate Addons for Elementor plugin <= 1.24.1 - Registration Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-elementor\/vulnerability\/wordpress-ultimate-addons-for-elementor-plugin-1-24-1-registration-bypass-vulnerability","description":"Registration Bypass vulnerability discovered by WordFence in WordPress Ultimate Addons for Elementor plugin (versions <= 1.24.1).","date":"2020-05-06"},{"id":"a1b50436-5d00-4964-ba51-f91756e17b0f","name":"Ultimate Addons for Elementor &lt; 1.24.2 - Registration Bypass","link":"https:\/\/wpscan.com\/vulnerability\/a1b50436-5d00-4964-ba51-f91756e17b0f","description":"&quot;The Ultimate Addons for Elementor plugin recently patched a vulnerability in version 1.24.2 that allows attackers to create subscriber-level users, even if registration is disabled on a WordPress site.&quot;\r\n\r\nThis vulnerability is being used in conjunction with a 0-day vulnerability in Elementor PRO.","date":null},{"id":"be89f58318ba9a70f281ddfbd6f73f7e153c9ed6","name":"Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-elementor\/ultimate-addons-for-elementor-1241-registration-bypass","description":"An issue was discovered in the \"Ultimate Addons for Elementor\" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.","date":"2020-05-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"3.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"3.9","impact":"2.5"}}},{"uuid":"2e23950005ff203ee9d7d0b20fe39b414976229457dcc045cfda1d7c7155bb79","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.20.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7a097a1f7ce07e437e94720797a7c2c2bc46b550","name":"WordPress Ultimate Addons for Elementor plugin <= 1.20.0 - Authentication Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-elementor\/vulnerability\/wordpress-ultimate-addons-for-elementor-plugin-1-20-0-authentication-bypass-vulnerability","description":"Authentication Bypass vulnerability found by MalCare in WordPress Ultimate Addons for Elementor plugin (versions <= 1.20.0).","date":"2019-12-12"}],"impact":[]},{"uuid":"745124f0735bd699f0beef870f521ac5ea08a86c0d0429e18d2f1237cd8be4d3","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.20.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e17430d9-f70f-40de-ad37-53810a96b2fc","name":"Ultimate Addons for Elementor &lt; 1.20.1 - Authentication Bypass","link":"https:\/\/wpscan.com\/vulnerability\/e17430d9-f70f-40de-ad37-53810a96b2fc","description":"A vulnerability affecting the Ultimate Addons for Elementor WordPress plugin allows malicious users to authenticate as any other user due to the lack of checks when logging in via Facebook or Google.","date":null}],"impact":[]},{"uuid":"e692c8d868463ba2118acbc667162264313f173ac4d6591421a1a74339cc064a","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.20.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9f47915ce22aa21a7dc9b6a8529108d06cda5ae9","name":"Ultimate Addons for Elementor < 1.20.1 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-elementor\/ultimate-addons-for-elementor-1201-authentication-bypass","description":"The Ultimate Addons for Elementor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when logging in by Google or Facebook in versions up to, and including, 1.20.0. This makes it possible for attackers to authenticate as any other user, including an administrator.","date":"2019-12-12"}],"impact":[]},{"uuid":"0f2ef2291f8a01e48d6d3127711d46f5f1d74875ada485c509a4248da94f5506","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.36.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.36.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-50890","name":"CVE-2023-50890","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-50890","description":"[en] Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n\/a through 1.36.20.","date":"2024-05-17"},{"id":"5489fa0fa76d894617306bc2d5d2e5a8d6af861d","name":"WordPress  Ultimate Addons for Elementor Plugin  <= 1.36.20 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-elementor\/vulnerability\/wordpress-ultimate-addons-for-elementor-plugin-1-36-20-privilege-escalation-vulnerability","description":"Update the WordPress Ultimate Addons for Elementor plugin to the latest available version (at least 1.36.21).\nRafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Ultimate Addons for Elementor Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 1.36.21.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-26"},{"id":"6d80da50104dede430584885194f9d66a0335063","name":"Ultimate Addons for Elementor <= 1.36.20 - Authenticated (Contributor+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-elementor\/ultimate-addons-for-elementor-13620-authenticated-contributor-privilege-escalation","description":"The Ultimate Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.36.20. This makes it possible for authenticated attackers, with contributor-level access and above, to register as an administrator on vulnerable sites.","date":"2023-12-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1fb5ee82abf535ea7817770b88031fedf4ec085f35de9da46a921873c49c74a2","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.36.32","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.36.32","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37455","name":"CVE-2024-37455","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37455","description":"[en] Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n\/a through 1.36.31.","date":"2024-07-09"},{"id":"bd4fee959309fae418f6b4e2450f571ac92e50ff","name":"WordPress Ultimate Addons for Elementor Plugin <= 1.36.31 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-elementor\/vulnerability\/wordpress-ultimate-addons-for-elementor-plugin-1-36-31-privilege-escalation-vulnerability","description":"<p>WordPress Ultimate Addons for Elementor Plugin <= 1.36.31 is vulnerable to Privilege Escalation<\/p><p>Affected Version <= 1.36.31<\/p><p>Fixed in version 1.36.32 <\/p>","date":"2024-07-01"},{"id":"fd68191c8eadd27f1175b98cc84b808d4a67f580","name":"Ultimate Addons for Elementor <= 1.36.31 - Authenticated (Contributor+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-elementor\/ultimate-addons-for-elementor-13631-authenticated-contributor-privilege-escalation","description":"The Ultimate Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.36.31. This makes it possible for authenticated attackers, with contributor-level access and above, to register as an administrator on vulnerable sites.","date":"2024-07-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"9e8e303ad2f85e33329e1597a76c1cc2337043d03c2644dbac5914b6bd107d15","name":"Ultimate Addons for Elementor [ultimate-elementor] < 1.45.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.45.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-66688","name":"CVE-2026-66688","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66688","description":"[en] Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.","date":"2026-08-06"},{"id":"677d3c63f0acaab510cd62a24571ba49ada4f4cc","name":"Ultimate Addons for Elementor <= 1.45.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/456377ec-1a73-4f9b-9fdf-0b5597e78aa5","description":"The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.45.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1786172332"}