Impact
The plugin contains an arbitrary file download flaw identified by CWE‑22. An attacker can instruct the vulnerable plugin to serve any file residing on the WordPress server filesystem, potentially exposing configuration files, credentials, or other sensitive data. The flaw allows reading data that should be protected, effectively compromising confidentiality.
Affected Systems
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) by Unlimited Elements. Versions up to 2.0.14 are vulnerable. Any WordPress site that has the plugin installed at these versions is affected.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a medium‑severity issue. No EPSS score is available and the vulnerability is not listed in CISA’s KEV, indicating no confirmed exploit yet, but the lack of a path‑restriction check means attackers can trigger the flaw by crafting a URL to the download endpoint. If the site is publicly accessible, an adversary could easily retrieve arbitrary files, which may include sensitive configuration or code files. The risk is limited to confidentiality, with no denial of service or code execution.
OpenCVE Enrichment