Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Unlimited Elements For Elementor plugin contains a reflected cross‑site scripting flaw. Unsanitized input that is incorporated into the rendered page allows an attacker to inject arbitrary JavaScript that executes in the browser context of any visitor to the affected site. Based on the description, it is inferred that the vulnerability can be triggered without authentication or additional privileges; a malicious request containing the payload is sufficient.

Affected Systems

Organizations running Unlimited Elements For Elementor (Free Widgets, Addons, Templates) with any version up to and including 2.0.12 are susceptible. All installations of these versions should be considered at risk until an update is applied.

Risk and Exploitability

The CVSS score of 7.1 indicates a high potential impact if exploited. The EPSS score of less than 1% shows a low probability of exploitation in real‑world attacks, indicating that the vulnerability is not frequently used. Nevertheless, an attacker can still trigger the reflected XSS flaw by sending a crafted request, executing arbitrary JavaScript in the browser context of any visitor; based on the description, it is inferred that no authentication or special privileges are required.

Generated by OpenCVE AI on August 1, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Use the vendor’s release notes to stay aware of any patch that addresses the XSS flaw and upgrade the plugin to the latest available version.
  • Deploy or configure a web application firewall to block or neutralize reflected XSS attempts directed at the plugin’s output.
  • If a fix is not yet available, consider disabling the plugin until an updated release is issued.
  • As a temporary mitigative measure, ensure that any data derived from the plugin is escaped or sanitized before rendering in templates, leveraging WordPress functions such as wp_kses().

Generated by OpenCVE AI on August 1, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Unlimited-elements
Unlimited-elements unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress
Wordpress wordpress
Vendors & Products Unlimited-elements
Unlimited-elements unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.
Title WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.12 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Unlimited-elements Unlimited Elements For Elementor (free Widgets, Addons, Templates)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.756Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57718

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:07.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')