Impact
An unauthenticated Cross Site Scripting flaw exists in the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin. This vulnerability allows an attacker to inject arbitrary JavaScript into a web page, resulting in client‑side code execution. The injected script can steal user credentials, hijack sessions, or deface the site, thereby compromising the confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
The affected product is the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin distributed by Unlimited Elements. Versions 2.0.17 and earlier are vulnerable. Any WordPress site that has not upgraded beyond 2.0.17 is susceptible to exploitation.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating a high impact severity. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can craft a malicious URL or payload that the plugin renders without sanitization; exploitation requires no user authentication, so anyone who can load the crafted URL is at risk.
OpenCVE Enrichment