PatchSiren

Unlimited Elements CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Unlimited Elements CVE published 2026-08-06

CVE-2026-28146

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:16:53.087Z and has not been modified since then. The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin version <= 2.0.14 contains a vulnerability allowing contributors to download arbitrary files. This vulnerability has a CVSS score of 6.5 and a MEDIUM severity level. W [truncated]

HIGH Unlimited Elements CVE published 2026-07-20

CVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output. This allows unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor of any WP page displaying that Place ID's reviews. The vulne [truncated]

HIGH Unlimited Elements CVE published 2026-07-13

CVE-2026-57718

CVE-2026-57718 is a Reflected Cross-Site Scripting (XSS) vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates). The issue affects versions from n/a through 2.0.12. Users should update to a patched version to prevent exploitation. This vulnerability has a CVSS score of 7.1 and is considered HIGH severity. It occurs when user input is not properly sanitized, allowing attackers [truncated]

HIGH Unlimited Elements CVE published 2026-05-25

CVE-2026-48837

A blind SQL injection vulnerability exists in the WordPress plugin Unlimited Elements For Elementor, affecting versions up to and including 2.0.8. The vulnerability stems from improper neutralization of special elements in SQL commands (CWE-89), allowing authenticated attackers with low privileges to manipulate database queries. The CVSS 3.1 score of 8.5 (High severity) reflects network attack vector, low [truncated]