CyberRota Analysis
AI-GeneratedThe Header Footer Builder for Elementor plugin in WordPress versions prior to 1.2.1 is vulnerable due to inadequate access controls, allowing users with the edit_posts capability to import potentially malicious templates. This can lead to the injection of JavaScript that executes in the context of any visitor or administrator, posing a risk of session hijacking or other malicious activities. WordPress site administrators and developers using this plugin should prioritize applying the update to mitigate these risks.
Original NVD Description
The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to display site-wide, injecting JavaScript that executes in the session of any visitor or administrator who loads the site.