Description
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
Published: 2026-08-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains an arbitrary file download flaw identified by CWE‑22. An attacker can instruct the vulnerable plugin to serve any file residing on the WordPress server filesystem, potentially exposing configuration files, credentials, or other sensitive data. The flaw allows reading data that should be protected, effectively compromising confidentiality.

Affected Systems

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) by Unlimited Elements. Versions up to 2.0.14 are vulnerable. Any WordPress site that has the plugin installed at these versions is affected.

Risk and Exploitability

The CVSS score of 6.5 classifies this as a medium‑severity issue. No EPSS score is available and the vulnerability is not listed in CISA’s KEV, indicating no confirmed exploit yet, but the lack of a path‑restriction check means attackers can trigger the flaw by crafting a URL to the download endpoint. If the site is publicly accessible, an adversary could easily retrieve arbitrary files, which may include sensitive configuration or code files. The risk is limited to confidentiality, with no denial of service or code execution.

Generated by OpenCVE AI on August 6, 2026 at 16:16 UTC.

Remediation

Vendor Solution

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.15).


OpenCVE Recommended Actions

  • Update the plugin to the latest release, at least 2.0.15.
  • Disable or uninstall the plugin if an upgrade is not feasible to eliminate the vulnerability.
  • If downtime is unavoidable, consider restricting access to the download endpoint to authenticated users or applying path validation logic as a custom security measure.

Generated by OpenCVE AI on August 6, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Unlimited-elements
Unlimited-elements unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress
Wordpress wordpress
Vendors & Products Unlimited-elements
Unlimited-elements unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
Title WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Unlimited-elements Unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:12.542Z

Reserved: 2026-02-25T12:14:24.000Z

Link: CVE-2026-28146

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')