PatchSiren

Unlimited Elements CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Unlimited Elements CVE published 2026-10-07

CVE-2026-95534

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress has a PHP Object Injection vulnerability due to deserialization of untrusted data. This issue affects versions from n/a through 2.0.19. The vulnerability could allow attackers to inject malicious objects, potentially leading to security issues. Defenders should assess exposure and prioritize updates to mitigate pot [truncated]

HIGH Unlimited Elements CVE published 2026-10-07

CVE-2026-94662

A Cross Site Scripting (XSS) vulnerability exists in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin versions up to 2.0.19. This issue allows for Stored XSS, potentially impacting users who interact with affected pages. The vulnerability arises from improper neutralization of input during web page generation. Evidence is limited, and specific details on exploitation and impact re [truncated]

MEDIUM Unlimited Elements CVE published 2026-10-05

CVE-2026-105064

CVE-2026-105064 is a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates). This vulnerability allows parameter injection, potentially leading to security issues. Affected versions range from n/a through 2.0.22. Defenders and administrators should assess exposure and prioritize remediation. The [truncated]

CRITICAL Unlimited Elements CVE published 2026-10-04

CVE-2026-103355

A critical SQL injection vulnerability exists in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin versions up to 2.0.20. This issue allows for Blind SQL Injection, posing a significant risk to affected systems. The vulnerability arises from improper neutralization of special elements used in an SQL command. Defenders and security teams should assess exposure and prioritize remedia [truncated]

HIGH Unlimited Elements CVE published 2026-10-04

CVE-2026-103344

A Cross-site Scripting (XSS) vulnerability exists in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin, affecting versions from n/a through 2.0.20. This issue allows for Reflected XSS attacks. The vulnerability is triggered when user input is not properly sanitized, leading to potential malicious script execution. Defenders should assess exposure and apply remediation to prevent po [truncated]

HIGH Unlimited Elements CVE published 2026-10-03

CVE-2026-103342

CVE-2026-103342 is a Cross-site Scripting vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress, affecting versions from n/a through 2.0.20. The vulnerability allows Reflected XSS attacks. Defenders and security teams responsible for WordPress installations with the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin should assess ex [truncated]

MEDIUM Unlimited Elements CVE published 2026-10-03

CVE-2026-92923

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 is vulnerable to blind SQL injection attacks. Users with a role as low as subscriber can exploit this issue, although version 2.0.18 removed subscriber-level access, requiring a Contributor role or above for exploitation. This vulnerability allows attackers to read arbitrary data from the database, potentially leading to data breaches. De [truncated]

MEDIUM Unlimited Elements CVE published 2026-10-03

CVE-2026-85568

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 is vulnerable to SQL injection attacks. This vulnerability allows unauthenticated users to retrieve non-public content when a related widget option is set away from its default. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. Defenders should assess exposure and verify the plugin version to prevent SQL injection attack [truncated]

HIGH Unlimited Elements CVE published 2026-09-20

CVE-2026-85017

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 is vulnerable to arbitrary PHP object injection. Authenticated attackers with subscriber-level access can exploit this issue by injecting attacker-controlled data through an AJAX action, which deserializes the input. Partial fixes in versions 2.0.18 and 2.0.19 raised the required privilege to editor-level, but the issue was fully resolved [truncated]

HIGH Unlimited Elements CVE published 2026-09-08

CVE-2026-84820

CVE-2026-84820 is a high-severity unauthenticated Cross Site Scripting (XSS) vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions up to 2.0.17. The vulnerability has a CVSS score of 7.1 and is considered high risk. Defenders and security teams responsible for WordPress installations with the Unlimited Elements For Elementor plugin should assess exposure and apply pa [truncated]

MEDIUM Unlimited Elements CVE published 2026-08-06

CVE-2026-28146

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:16:53.087Z and has not been modified since then. The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin version <= 2.0.14 contains a vulnerability allowing contributors to download arbitrary files. This vulnerability has a CVSS score of 6.5 and a MEDIUM severity level. W [truncated]

HIGH Unlimited Elements CVE published 2026-07-20

CVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output. This allows unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor of any WP page displaying that Place ID's reviews. The vulne [truncated]

HIGH Unlimited Elements CVE published 2026-07-13

CVE-2026-57718

CVE-2026-57718 is a Reflected Cross-Site Scripting (XSS) vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates). The issue affects versions from n/a through 2.0.12. Users should update to a patched version to prevent exploitation. This vulnerability has a CVSS score of 7.1 and is considered HIGH severity. It occurs when user input is not properly sanitized, allowing attackers [truncated]

HIGH Unlimited Elements CVE published 2026-05-25

CVE-2026-48837

A blind SQL injection vulnerability exists in the WordPress plugin Unlimited Elements For Elementor, affecting versions up to and including 2.0.8. The vulnerability stems from improper neutralization of special elements in SQL commands (CWE-89), allowing authenticated attackers with low privileges to manipulate database queries. The CVSS 3.1 score of 8.5 (High severity) reflects network attack vector, low [truncated]