Description
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.
Published: 2026-09-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Unlimited Elements For Elementor WordPress plugin before version 2.0.20 lacks a capability check on an AJAX action and deserializes attacker‑controlled data, an insecure deserialization flaw (CWE‑502), enabling authenticated users with subscriber-level access to inject arbitrary PHP objects, which permits execution of arbitrary PHP code within the context of the website, leading to a compromise of confidentiality, integrity and availability.

Affected Systems

WordPress sites that incorporate the Unlimited Elements For Elementor plugin at a version older than 2.0.20 are vulnerable; the plugin was vulnerable to PHP object injection for subscribers before 2.0.18, to editors between 2.0.18 and 2.0.19, and was fully patched in 2.0.20 and thereafter.

Risk and Exploitability

Because the flaw requires authentication (subscriber or higher), the attack surface is limited to sites that expose the vulnerable AJAX action to logged‑in users; the CVSS score is 7.5, indicating high severity, and the EPSS score is < 1%, so known exploitation is low at present. The potential for arbitrary PHP execution grants the flaw a high impact rating, and the absence of a KEV listing indicates no known exploitation yet; however, the vulnerability and its exploitability warrant prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Unlimited Elements For Elementor plugin to version 2.0.20 or later.
  • If upgrading is delayed, limit plugin usage to accounts with editor role or higher, and block access to the AJAX endpoint for subscriber users.
  • Monitor WordPress logs for anomalous AJAX requests to the plugin’s endpoint and review subscriber data for injected PHP objects.

Generated by OpenCVE AI on September 20, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions unlimited Elements For Elementor
Vendors & Products Wordpress-extensions
Wordpress-extensions unlimited Elements For Elementor

Sun, 20 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-502

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.
Title Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection
References

Subscriptions

Wordpress-extensions Unlimited Elements For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:49:34.242Z

Reserved: 2026-09-02T19:18:51.316Z

Link: CVE-2026-85017

cve-icon Vulnrichment

Updated: 2026-09-20T13:49:13.859Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:50.303

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-85017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:44Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data