Impact
The Unlimited Elements For Elementor WordPress plugin before version 2.0.20 lacks a capability check on an AJAX action and deserializes attacker‑controlled data, an insecure deserialization flaw (CWE‑502), enabling authenticated users with subscriber-level access to inject arbitrary PHP objects, which permits execution of arbitrary PHP code within the context of the website, leading to a compromise of confidentiality, integrity and availability.
Affected Systems
WordPress sites that incorporate the Unlimited Elements For Elementor plugin at a version older than 2.0.20 are vulnerable; the plugin was vulnerable to PHP object injection for subscribers before 2.0.18, to editors between 2.0.18 and 2.0.19, and was fully patched in 2.0.20 and thereafter.
Risk and Exploitability
Because the flaw requires authentication (subscriber or higher), the attack surface is limited to sites that expose the vulnerable AJAX action to logged‑in users; the CVSS score is 7.5, indicating high severity, and the EPSS score is < 1%, so known exploitation is low at present. The potential for arbitrary PHP execution grants the flaw a high impact rating, and the absence of a KEV listing indicates no known exploitation yet; however, the vulnerability and its exploitability warrant prompt remediation.
OpenCVE Enrichment