Segurium Research Advisories header-footer-elementor

Ultimate Addons for Elementor 2.9.3 and earlier: Insecure direct object reference

medium Insecure direct object reference

The [hfe_template] shortcode in Ultimate Addons for Elementor used a status denylist, so scheduled, trashed and non-public posts could render to visitors who may not view them. Release 2.9.4 switches to an allowlist and drops the plugin's own SVG sanitiser.

Plugin
Ultimate Addons for Elementor header-footer-elementor
Affected versions
2.9.3 and earlier
Fixed in
2.9.4
Class
Insecure direct object reference
Severity
medium Segurium Research assessment. No CVSS score published yet.
CVE
None assigned at the time of writing
Installs
2,000,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.