PatchSiren cyber security CVE debrief
CVE-2026-27041 Studio Keren Aga LTD. CVE debrief
A critical vulnerability (CVSS Score: 9.9) was discovered in the Unlimited Elements for Elementor (Premium) plugin, version 2.0.6 and earlier. This vulnerability allows contributors to upload arbitrary files, potentially leading to severe consequences, including code execution and data breaches. The vulnerability was made public on June 17, 2026. Users of this plugin should immediately apply patches or updates to mitigate this risk. The vendor, Unknown Vendor, has not provided a canonical source, but Patchstack has reported this vulnerability. No ransomware campaigns have been linked to this vulnerability.
- Vendor
- Studio Keren Aga LTD.
- Product
- Unlimited Elements for Elementor (Premium)
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of the Unlimited Elements for Elementor (Premium) plugin, version 2.0.6 and earlier, should be aware of this critical vulnerability. Immediate action is required to prevent potential exploitation.
Technical summary
The CVE-2026-27041 vulnerability is a critical arbitrary file upload issue in the Unlimited Elements for Elementor (Premium) plugin. This vulnerability, with a CVSS score of 9.9, allows contributors to upload files without proper restrictions, potentially leading to code execution. The vulnerability is characterized by CWE-434. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating a high severity level.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates to the Unlimited Elements for Elementor (Premium) plugin immediately.
- Restrict file uploads to only trusted users.
- Monitor plugin usage and file uploads for suspicious activity.
- Implement additional security measures, such as web application firewalls (WAFs).
- Regularly update and patch all plugins and software.
- Consider replacing the plugin if no patch is available.
Evidence notes
The vulnerability was reported by Patchstack and is listed in the NVD database. The CVE record was created on June 17, 2026. The vendor, Unknown Vendor, has not provided a canonical source. The vulnerability has not been linked to any ransomware campaigns.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27041 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27041
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27041 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27041
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.