Input validation vulnerability in Elementor Header & Footer Builder 1.6.45

The plugin called “Elementor Header & Footer Builder” for WordPress has a security issue. This happens when someone uploads an SVG file using the REST API feature. This vulnerability affects all versions up to 1.6.45. The problem is that the plugin does not properly check the input from users and does not protect against harmful scripts. This means that someone with at least Author-level access can add their own code to a page and it will run when someone views the SVG file.

Detected in:

Elementor Header & Footer Builder fixed vulnerable versions: >= * <= 1.6.45
Ultimate Addons for Elementor fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.