Impact
The flaw is a missing authorization weakness in the Unlimited Elements for Elementor plugin that lets attackers bypass intended permission restrictions. This unauthorized access can enable users to view or alter data that should be limited to privileged accounts. The vulnerability is cataloged as Incorrect Access Control (CWE‑862). The primary impact is an escalation of privileges and potential data modification or disclosure.
Affected Systems
All releases of the Unlimited Elements for Elementor (Free Widgets, Addons, Templates) plugin, up to and including version 2.0.17, are affected. No later releases are mentioned as vulnerable, so the issue is confined to the stated versions.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate severity range. EPSS data is not available, so the probability of real‑world exploitation remains unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could leverage crafted requests to the plugin’s administrative endpoints to bypass permission checks, but specific exploit steps are not detailed in the provided data.
OpenCVE Enrichment