Segurium Research Advisories header-footer-elementor
Ultimate Addons for Elementor 2.9.3 and earlier: Insecure direct object reference
The [hfe_template] shortcode in Ultimate Addons for Elementor used a status denylist, so scheduled, trashed and non-public posts could render to visitors who may not view them. Release 2.9.4 switches to an allowlist and drops the plugin's own SVG sanitiser.
- Plugin
- Ultimate Addons for Elementor
header-footer-elementor - Affected versions
- 2.9.3 and earlier
- Fixed in
2.9.4- Class
- Insecure direct object reference
- Severity
- medium Segurium Research assessment. No CVSS score published yet.
- CVE
- None assigned at the time of writing
- Installs
- 2,000,000 active
- Patch released
- Sources