Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that enables attackers to inject arbitrary scripts that are stored by the plugin. When the malicious input is processed by the Unlimited Elements For Elementor plugin and preserved in the database, any visitor to the affected site receives the injected code. This Stored Cross‑Site Scripting (CWE‑79) can be used for cookie theft, session hijacking, defacement or forcing download of malware, thereby compromising the confidentiality, integrity and availability of the web application.
Affected Systems
The affected product is Unlimited Elements For Elementor (Free Widgets, Addons, Templates) released by Unlimited Elements. All releases from the earliest version up to and including 2.0.19 are known to be vulnerable. No specific version thresholds are listed apart from the 2.0.19 boundary.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS is not available so the likelihood of exploitation cannot be quantified, but it is not listed in CISA’s KEV catalog, suggesting no confirmed large‑scale exploits to date. An attacker would most likely need access to the WordPress backend or the ability to submit content via the plugin. Once the script is stored, every site visitor is affected, raising the potential impact to the entire user base of a site. Because the flaw is stored XSS, the risk remains high until the plugin is updated.
OpenCVE Enrichment