Unauthorized Data Modification Vulnerability in Elementor Addon by Brainstorm Force
CVE-2025-8488

4.3MEDIUM

What is CVE-2025-8488?

The Ultimate Addons for Elementor plugin, developed by Brainstorm Force, is prone to a serious vulnerability due to a lack of proper capability verification within the save_hfe_compatibility_option_callback() function. This flaw permits attackers with at least Subscriber privileges to manipulate the compatibility option settings, posing a significant risk to site integrity and data control. Users of all versions up to and including 2.4.6 are potentially affected, underscoring the importance of maintaining updated security measures.

Affected Version(s)

Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) * <= 2.4.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.
CVE-2025-8488 : Unauthorized Data Modification Vulnerability in Elementor Addon by Brainstorm Force