Description
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-02-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross‑Site Scripting via the Border Hero widget’s Button Link field. Because the plugin does not properly sanitize or escape user supplied URLs, an authenticated user with Contributor or higher privileges can embed arbitrary JavaScript that will run whenever a page containing the widget is viewed. This flaw is a classic input validation weakness identified as CWE‑79 and can lead to session hijacking, defacement, or execution of malicious payloads on victim browsers.

Affected Systems

The affected product is the UniteCMS Unlimited Elements for Elementor WordPress plugin, specifically versions up to and including 2.0.1. Any WordPress site running these versions is susceptible when the Border Hero widget is used. Control of the site by a Contributor or higher level user enables exploitation.

Risk and Exploitability

The CVSS base score of 5.4 places it in the moderate range, and the EPSS score of less than 1% indicates a low probability of observed exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated Contributor+ user to modify the button link field in the widget; the malicious content is persisted to the database and executed for all site visitors. While the likelihood of exploitation is limited to sites with the vulnerable plugin and active contributor accounts, the potential impact on confidentiality and integrity of user sessions is significant.

Generated by OpenCVE AI on April 21, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Unlimited Elements for Elementor plugin to the latest version that removes the unsafe sanitization in the Border Hero widget (v2.0.2 or newer).
  • Delete or clean any existing Border Hero widget instances that contain user‑supplied Button Link values, ensuring no stored XSS payloads remain.
  • Apply a robust Content Security Policy that blocks inline script execution from user input, providing a defensive layer until the plugin is fully patched.

Generated by OpenCVE AI on April 21, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 04 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Unitecms
Unitecms unlimited Elements For Elementor
Unlimited-elements
Unlimited-elements unlimited Elements For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Unitecms
Unitecms unlimited Elements For Elementor
Unlimited-elements
Unlimited-elements unlimited Elements For Elementor
Wordpress
Wordpress wordpress

Tue, 03 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Unitecms Unlimited Elements For Elementor
Unlimited-elements Unlimited Elements For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:50:09.598Z

Reserved: 2025-12-08T16:10:50.434Z

Link: CVE-2025-14274

cve-icon Vulnrichment

Updated: 2026-02-03T15:59:21.130Z

cve-icon NVD

Status : Deferred

Published: 2026-02-03T06:15:52.087

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T16:15:40Z

Weaknesses