The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.
References
Configurations
No configuration.
History
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 Aug 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-02 10:15
Updated : 2025-08-04 15:06
NVD link : CVE-2025-8488
Mitre link : CVE-2025-8488
CVE.ORG link : CVE-2025-8488
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization