Unauthorized Data Modification Vulnerability in Elementor Addon by Brainstorm Force
CVE-2025-8488
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 August 2025
What is CVE-2025-8488?
The Ultimate Addons for Elementor plugin, developed by Brainstorm Force, is prone to a serious vulnerability due to a lack of proper capability verification within the save_hfe_compatibility_option_callback() function. This flaw permits attackers with at least Subscriber privileges to manipulate the compatibility option settings, posing a significant risk to site integrity and data control. Users of all versions up to and including 2.4.6 are potentially affected, underscoring the importance of maintaining updated security measures.
Affected Version(s)
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) * <= 2.4.6