Unlimited Elements For Elementor <= 2.0.14 - Authenticated (Contributor+) Arbitrary File Download
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.14. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive inf...
- CVSS:
- 6.5
- Affected:
- up to 2.0.14
- Fixed in:
- 2.0.15
- Disclosed:
- Aug 3, 2026
CVE-2026-28146 on NVD →
Unlimited Elements For Elementor <= 2.0.15 - Missing Authorization
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.16
- Disclosed:
- Aug 3, 2026
CVE-2026-28147 on NVD →
Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting
high
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute when...
- CVSS:
- 7.2
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.13
- Disclosed:
- Jul 9, 2026
CVE-2026-57718 on NVD →
Unlimited Elements for Elementor <= 2.0.10 - Unauthenticated Stored Cross-Site Scripting
high
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute when...
- CVSS:
- 7.2
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Jun 29, 2026
CVE-2026-10081 on NVD →
Unlimited Elements For Elementor <= 2.0.8 - Authenticated (Contributor+) SQL Injection
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-...
- CVSS:
- 6.5
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- May 26, 2026
CVE-2026-48837 on NVD →
Unlimited Elements For Elementor <= 2.0.7 - Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter
medium
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the use of deprecated escaping functions combined with direct strin...
- CVSS:
- 6.5
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- May 13, 2026
CVE-2026-5486 on NVD →
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.5.140
- Fixed in:
- 1.5.141
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal
high
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable de...
- CVSS:
- 7.5
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Apr 16, 2026
CVE-2026-4659 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) - Unauthenticated Stored Cross-Site Scripting via Form Entry Fields vulnerability
high
Unauthenticated Stored Cross-Site Scripting via Form Entry Fields vulnerability
- CVSS:
- 7.1
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Mar 11, 2026
Unlimited Elements For Elementor <= 2.0.5 - Unauthenticated Stored Cross-Site Scripting via Form Entry Fields
high
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This ma...
- CVSS:
- 7.2
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Mar 9, 2026
CVE-2026-2724 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2
unknown
[en] The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Feb 3, 2026
CVE-2025-14274 on NVD →
Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget
medium
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, wit...
- CVSS:
- 5.4
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Feb 2, 2026
CVE-2025-14274 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.1
unknown
[en] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 27, 2025
CVE-2025-13692 on NVD →
Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) <= 2.0 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
high
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 7.2
- Affected:
- up to 2.0
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 26, 2025
CVE-2025-13692 on NVD →
Unlimited Elements For Elementor <= 1.5.148 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above...
- CVSS:
- 6.4
- Affected:
- up to 1.5.148
- Fixed in:
- 1.5.149
- Disclosed:
- Aug 27, 2025
CVE-2025-8603 on NVD →
Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above...
- CVSS:
- 6.4
- Affected:
- up to 1.5.142
- Fixed in:
- 1.5.143
- Disclosed:
- Apr 2, 2025
CVE-2025-1663 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141
unknown
[en] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- Affected:
- up to 1.5.141
- Fixed in:
- 1.5.141
- Disclosed:
- Feb 20, 2025
CVE-2024-13155 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 1.5.140
- Fixed in:
- 1.5.141
- Disclosed:
- Feb 19, 2025
CVE-2024-13155 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.135
unknown
[en] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 1.5.135
- Fixed in:
- 1.5.135
- Disclosed:
- Jan 9, 2025
CVE-2024-13153 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 1.5.135
- Fixed in:
- 1.5.136
- Disclosed:
- Jan 8, 2025
CVE-2024-13153 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.127
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- Affected:
- up to 1.5.127
- Fixed in:
- 1.5.127
- Disclosed:
- Dec 12, 2024
CVE-2024-10784 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 1.5.126
- Fixed in:
- 1.5.127
- Disclosed:
- Dec 11, 2024
CVE-2024-10784 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122
unknown
[en] : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows : Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.
- Affected:
- up to 1.5.122
- Fixed in:
- 1.5.122
- Disclosed:
- Oct 16, 2024
CVE-2024-49271 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.121 - Authenticated (Editor+) Remote Code Execution
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.121 via the template engine. This is due to the plugin not properly restricting functions that can be called and passed to code execution functions...
- CVSS:
- 7.2
- Affected:
- up to 1.5.121
- Fixed in:
- 1.5.122
- Disclosed:
- Oct 14, 2024
CVE-2024-49271 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a thr...
- Affected:
- up to 1.5.122
- Fixed in:
- 1.5.122
- Disclosed:
- Oct 6, 2024
CVE-2024-45454 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.121 - Reflected Cross-Site Scripting
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.121 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 6.1
- Affected:
- up to 1.5.121
- Fixed in:
- 1.5.122
- Disclosed:
- Sep 30, 2024
CVE-2024-45454 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...
- Affected:
- up to 1.5.113
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 9, 2024
CVE-2024-6169 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possi...
- Affected:
- up to 1.5.113
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 9, 2024
CVE-2024-6171 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
- Affected:
- up to 1.5.113
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 9, 2024
CVE-2024-6170 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- Affected:
- up to 1.5.113
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 9, 2024
CVE-2024-6166 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injection
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...
- CVSS:
- 8.8
- Affected:
- up to 1.5.112
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 8, 2024
CVE-2024-6166 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'username'
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...
- CVSS:
- 6.4
- Affected:
- up to 1.5.112
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 8, 2024
CVE-2024-6169 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'email'
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 1.5.112
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 8, 2024
CVE-2024-6170 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible f...
- CVSS:
- 5.3
- Affected:
- up to 1.5.112
- Fixed in:
- 1.5.113
- Disclosed:
- Jul 8, 2024
CVE-2024-6171 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66
unknown
[en] Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65.
- Affected:
- up to 1.5.66
- Fixed in:
- 1.5.66
- Disclosed:
- Jun 9, 2024
CVE-2023-31080 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
- Affected:
- up to 1.5.110
- Fixed in:
- 1.5.110
- Disclosed:
- Jun 6, 2024
CVE-2024-5329 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...
- CVSS:
- 8.8
- Affected:
- up to 1.5.109
- Fixed in:
- 1.5.110
- Disclosed:
- Jun 5, 2024
CVE-2024-5329 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Information Exposure
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.109 due to missing restrictions on the getPostDataByObj() function. This makes it possible for authenticated attackers, with Contributor-l...
- CVSS:
- 4.3
- Affected:
- up to 1.5.109
- Fixed in:
- 1.5.110
- Disclosed:
- Jun 5, 2024
CVE-2024-35674 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110
unknown
[en] Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.109.
- Affected:
- up to 1.5.110
- Fixed in:
- 1.5.110
- Disclosed:
- Jun 5, 2024
CVE-2024-35674 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.
- Affected:
- up to 1.5.67
- Fixed in:
- 1.5.67
- Disclosed:
- Jun 4, 2024
CVE-2023-33930 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This make...
- Affected:
- up to 1.5.108
- Fixed in:
- 1.5.108
- Disclosed:
- May 30, 2024
CVE-2024-3190 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.107 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Field
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- CVSS:
- 5.4
- Affected:
- up to 1.5.107
- Fixed in:
- 1.5.108
- Disclosed:
- May 29, 2024
CVE-2024-3190 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.91
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute co...
- Affected:
- up to 1.5.91
- Fixed in:
- 1.5.91
- Disclosed:
- May 29, 2024
CVE-2023-6743 on NVD →
Unlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template import
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute code on...
- CVSS:
- 8.8
- Affected:
- up to 1.5.89
- Fixed in:
- 1.5.91
- Disclosed:
- May 28, 2024
CVE-2023-6743 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...
- Affected:
- up to 1.5.108
- Fixed in:
- 1.5.108
- Disclosed:
- May 23, 2024
CVE-2024-4779 on NVD →
Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[post_ids][0]
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...
- CVSS:
- 8.8
- Affected:
- up to 1.5.107
- Fixed in:
- 1.5.108
- Disclosed:
- May 22, 2024
CVE-2024-4779 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Contributor+) SQL Injection
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...
- CVSS:
- 8.8
- Affected:
- up to 1.5.102
- Fixed in:
- 1.5.105
- Disclosed:
- May 10, 2024
CVE-2024-3055 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authen...
- Affected:
- up to 1.5.103
- Fixed in:
- 1.5.103
- Disclosed:
- May 10, 2024
CVE-2024-2662 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S...
- Affected:
- up to 1.5.105
- Fixed in:
- 1.5.105
- Disclosed:
- May 10, 2024
CVE-2024-3055 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for u...
- Affected:
- up to 1.5.103
- Fixed in:
- 1.5.103
- Disclosed:
- May 10, 2024
CVE-2024-3547 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injection
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticat...
- CVSS:
- 7.2
- Affected:
- up to 1.5.102
- Fixed in:
- 1.5.103
- Disclosed:
- May 9, 2024
CVE-2024-2662 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauth...
- CVSS:
- 6.1
- Affected:
- up to 1.5.102
- Fixed in:
- 1.5.103
- Disclosed:
- May 9, 2024
CVE-2024-3547 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.61
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.
- Affected:
- up to 1.5.61
- Fixed in:
- 1.5.61
- Disclosed:
- Apr 24, 2024
CVE-2023-31090 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.97
unknown
[en] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link field of an installed widget (e.g., 'Button Link') in all versions up to, and including, 1.5.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...
- Affected:
- up to 1.5.97
- Fixed in:
- 1.5.97
- Disclosed:
- Mar 30, 2024
CVE-2024-0367 on NVD →
Unlimited Elements For Elementor <= 1.5.96 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link
medium
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link field of an installed widget (e.g., 'Button Link') in all versions up to, and including, 1.5.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...
- CVSS:
- 6.4
- Affected:
- up to 1.5.96
- Fixed in:
- 1.5.97
- Disclosed:
- Mar 29, 2024
CVE-2024-0367 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.94
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1....
- Affected:
- up to 1.5.94
- Fixed in:
- 1.5.94
- Disclosed:
- Mar 27, 2024
CVE-2024-29792 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.93 - Reflected Cross-Site Scripting
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.93 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.5.93
- Fixed in:
- 1.5.94
- Disclosed:
- Mar 25, 2024
CVE-2024-29792 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65.
- Affected:
- up to 1.5.66
- Fixed in:
- 1.5.66
- Disclosed:
- Dec 20, 2023
CVE-2023-31231 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.5.74
- Fixed in:
- 1.5.75
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.65 - Missing Authorization
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it poss...
- CVSS:
- 6.3
- Affected:
- up to 1.5.65
- Fixed in:
- 1.5.66
- Disclosed:
- Jun 20, 2023
CVE-2023-31080 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67
unknown
[en] The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor...
- Affected:
- up to 1.5.67
- Fixed in:
- 1.5.67
- Disclosed:
- Jun 17, 2023
CVE-2023-3295 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File Upload
high
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-leve...
- CVSS:
- 8.8
- Affected:
- up to 1.5.66
- Fixed in:
- 1.5.67
- Disclosed:
- Jun 16, 2023
CVE-2023-3295 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.60 - Arbitrary File Upload in File Manager
critical
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files within zip files in the File Manager functionality in versions up to, and including, 1.5.60 . This makes it possible for authenticated attackers, with...
- CVSS:
- 9.9
- Affected:
- up to 1.5.60
- Fixed in:
- 1.5.61
- Disclosed:
- May 22, 2023
CVE-2023-31090 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Zip Extraction to Arbitrary File Upload in File Manager
critical
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files within zip files in the File Manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with...
- CVSS:
- 9.9
- Affected:
- up to 1.5.66
- Fixed in:
- 1.5.67
- Disclosed:
- May 22, 2023
CVE-2023-33930 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.49
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.
- Affected:
- up to 1.5.49
- Fixed in:
- 1.5.49
- Disclosed:
- Mar 28, 2023
CVE-2022-47170 on NVD →
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.48 - Authenticated (Admin+) Cross Site Scripting (XSS)
medium
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 1.5.48 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrati...
- CVSS:
- 4.4
- Affected:
- up to 1.5.48
- Fixed in:
- 1.5.49
- Disclosed:
- Jan 27, 2023
CVE-2022-47170 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Mar 4, 2022
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Feb 28, 2022
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Feb 28, 2022
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.149
unknown
- Affected:
- up to 1.5.149
- Fixed in:
- 1.5.149
CVE-2025-8603 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.143
unknown
- Affected:
- up to 1.5.143
- Fixed in:
- 1.5.143
CVE-2025-1663 on NVD →
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
unknown
The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.75
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.5.75
- Fixed in:
- 1.5.75
CVE-2023-33999 on NVD →