PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-95534 Unlimited Elements CVE debrief

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress has a PHP Object Injection vulnerability due to deserialization of untrusted data. This issue affects versions from n/a through 2.0.19. The vulnerability could allow attackers to inject malicious objects, potentially leading to security issues. Defenders should assess exposure and prioritize updates to mitigate potential risks. The CVE record and source item provide details on the vulnerability but do not specify exploitation or impact.

Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders managing WordPress installations with the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin should assess exposure and prioritize updates. Security teams and vulnerability management teams should review the plugin's version and update if necessary to prevent potential object injection. Operators and platform administrators should monitor for suspicious activity related to the plugin.

Why it matters

Defenders should care about CVE-2026-95534 because it involves a PHP Object Injection vulnerability in the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress, which could lead to security issues if exploited.

  • Verify plugin version and update if necessary to prevent potential object injection.
  • Monitor for suspicious activity related to the plugin.

Technical summary

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress has a PHP Object Injection vulnerability due to deserialization of untrusted data. This issue affects versions from n/a through 2.0.19. The vulnerability could allow attackers to inject malicious objects, potentially leading to security issues. The plugin's vulnerability management and security teams should prioritize verifying and updating the plugin to a version beyond 2.0.19 if currently using an affected version. Defenders should assess exposure and prioritize updates to mitigate potential risks.

Defensive priority

Defenders should prioritize verifying and updating the plugin to a version beyond 2.0.19 if currently using an affected version.

Recommended defensive actions

  • Verify the version of Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin is beyond 2.0.19.
  • Update the plugin to the latest version if currently using an affected version.
  • Monitor for any suspicious activity related to the plugin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability but do not specify exploitation or impact. The NVD entry is currently empty. Defenders should verify plugin versions and monitor for suspicious activity related to the plugin. The vulnerability involves deserialization of untrusted data, which could lead to object injection. There is no information on known affected scope or exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-95534 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-95534

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-95534 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95534

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.