Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Published: 2026-10-04
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a reflected Cross‑Site Scripting flaw caused by insufficient input neutralization when the Unlimited Elements For Elementor plugin renders user‑supplied data. An attacker who can influence input that will be displayed on the site can inject malicious JavaScript. When a victim accesses a URL or interacts with the page, the script runs in their browser, allowing credential theft, session hijacking, defacement, or other client‑side attacks.

Affected Systems

Unlimited Elements For Elementor (Free Widgets, Addons, Templates), a WordPress plugin. Versions up to and including 2.0.20 are affected; the recommended safe version is 2.0.21 or later.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity flaw that can be exploited remotely over the web. The EPSS score is unavailable, so the exact attack probability is unknown, but reflected XSS is a common and well‑known technique. The vulnerability is not listed in CISA's KEV catalog. An attacker can trigger the flaw by crafting malicious URLs or inputs that are reflected in the page output, exploiting the lack of proper sanitization. The impact is limited to the compromised user session, not to the server itself.

Generated by OpenCVE AI on October 4, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21).


OpenCVE Recommended Actions

  • Update the Unlimited Elements For Elementor plugin to version 2.0.21 or later.
  • If an update is not possible, uninstall or disable the plugin until a fix is available.
  • Audit and sanitize any input that could be reflected in the plugin’s output to prevent future XSS vulnerabilities.

Generated by OpenCVE AI on October 4, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Title WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-04T08:00:09.427Z

Reserved: 2026-09-30T12:43:33.093Z

Link: CVE-2026-103344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T09:16:38.543

Modified: 2026-10-04T09:16:38.543

Link: CVE-2026-103344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T10:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')