Junglewise Threat Intelligence

CVE-2026-12869: Header Footer Builder for Elementor Stored XSS via Template Import

CVE-2026-12869 · Severity: info · CVSS 6.8 · Published 2026-07-16

Vendors: Brainstorm Force, Unknown.

Executive brief

A security vulnerability in the Header Footer Builder for Elementor plugin allows users with low-level 'Contributor' permissions to upload malicious templates to a WordPress site. These templates can contain hidden scripts that execute automatically for every visitor, including site administrators. This could lead to full website takeover, theft of administrator session cookies, or the redirection of visitors to malicious websites.

Technical details

The Header Footer Builder for Elementor plugin fails to implement proper authorization checks on its 'tahefobu_dashboard_import' AJAX action. While this action should be restricted to administrators, it is accessible to any user with 'edit_posts' capabilities (Contributor role and above). An attacker can exploit this by importing a specially crafted JSON template containing an Elementor HTML widget with a malicious JavaScript payload. Because the plugin allows these templates to be configured for site-wide display, the injected script executes in the context of any user—including administrators—who visits the site's front end. This is a stored Cross-Site Scripting (XSS) vulnerability fixed in version 1.2.1.

Affected products

  • Unknown Header Footer Builder for Elementor < 1.2.1

Timeline

  • 2026-06-25: disclosed: Publicly published by WPScan
  • 2026-07-16: advisory: NVD publication date

References