Header Footer Builder for Elementor WordPress Plugin Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Header Footer Builder for Elementor WordPress plugin, affecting versions prior to 1.2.1. The issue arises because the plugin's dashboard template-import action does not require administrative capabilities, allowing any user with the edit_posts permission, such as Contributors, to import templates. This can be exploited by injecting JavaScript into an Elementor HTML widget, which is then executed in the session of any visitor or administrator who loads the site.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected JavaScript is executed in the context of the user visiting the site, including administrators.

Reproduction

To reproduce this vulnerability, log in as a Contributor user on a WordPress site with the Header Footer Builder for Elementor plugin version 1.2.0 or earlier, and Elementor (free) active. Once logged in, navigate to the plugin's dashboard and scrape the nonce required for the template import action. Then, create a malicious template that includes an Elementor HTML widget set to display site-wide, injecting a JavaScript payload, such as an image tag with an onerror event. After importing the template, the JavaScript payload will execute in the browser of any visitor or administrator who loads the site.

Remediation

Users are advised to update the Header Footer Builder for Elementor WordPress plugin to version 1.2.1 or later.

Added: Jul 16, 2026, 7:24 AM
Updated: Jul 16, 2026, 7:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.