Impact
The Unlimited Elements for Elementor WordPress plugin, versions prior to 2.0.21, fails to sanitize file paths extracted from uploaded archive files, representing a CWE‑22 path traversal flaw. This flaw allows authenticated users who can access the asset‑management feature—Administrators by default or Editors if the plugin setting is altered—to write arbitrary files, including executable PHP, outside the intended upload directory on servers lacking the PHP zip extension. The consequence is remote code execution, enabling attackers to compromise site functionality and potentially host malicious payloads on the server.
Affected Systems
Plugins bundled with WordPress installations that use Unlimited Elements for Elementor earlier than version 2.0.21 are susceptible. The vulnerability is exploitable by authenticated users possessing editor or administrator privileges, depending on the plugin’s configuration. Sites running the PHP zip extension is absent are at greatest risk, while the presence of the extension mitigates the flaw’s exploitation path.
Risk and Exploitability
No public exploits or exploitation evidence is currently documented, and the EPSS score is < 1%. The CVSS score is 6.6, indicating moderate severity, but the vulnerability still facilitates remote code execution, a high‑risk impact. Attackers would need authenticated access to the asset‑management interface and a server configuration without the PHP zip extension. Because this condition is common on many WordPress hosts, the risk remains significant despite the lack of publicly known exploits. The vulnerability is not listed in CISA's KEV catalog, indicating no confirmed or widespread exploitation yet.
OpenCVE Enrichment