Impact
The Unlimited Elements For Elementor plugin contains a reflected cross‑site scripting flaw. Unsanitized input that is incorporated into the rendered page allows an attacker to inject arbitrary JavaScript that executes in the browser context of any visitor to the affected site. Based on the description, it is inferred that the vulnerability can be triggered without authentication or additional privileges; a malicious request containing the payload is sufficient.
Affected Systems
Organizations running Unlimited Elements For Elementor (Free Widgets, Addons, Templates) with any version up to and including 2.0.12 are susceptible. All installations of these versions should be considered at risk until an update is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact if exploited. The EPSS score of less than 1% shows a low probability of exploitation in real‑world attacks, indicating that the vulnerability is not frequently used. Nevertheless, an attacker can still trigger the reflected XSS flaw by sending a crafted request, executing arbitrary JavaScript in the browser context of any visitor; based on the description, it is inferred that no authentication or special privileges are required.
OpenCVE Enrichment