Input validation vulnerability in UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) 2.0.0

The UltraAddons Elementor Lite plugin for WordPress has a security issue called Stored Cross-Site Scripting in versions 2.0.0 and below. This is because it does not properly clean and protect user input and output. This allows attackers who are signed in with contributor or higher level access to add harmful web scripts to pages. These scripts will run whenever a user visits the affected page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.