Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS.

This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
Published: 2026-10-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Stored cross‑site scripting
Action: Apply patch
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation that enables attackers to inject arbitrary scripts that are stored by the plugin. When the malicious input is processed by the Unlimited Elements For Elementor plugin and preserved in the database, any visitor to the affected site receives the injected code. This Stored Cross‑Site Scripting (CWE‑79) can be used for cookie theft, session hijacking, defacement or forcing download of malware, thereby compromising the confidentiality, integrity and availability of the web application.

Affected Systems

The affected product is Unlimited Elements For Elementor (Free Widgets, Addons, Templates) released by Unlimited Elements. All releases from the earliest version up to and including 2.0.19 are known to be vulnerable. No specific version thresholds are listed apart from the 2.0.19 boundary.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. EPSS is not available so the likelihood of exploitation cannot be quantified, but it is not listed in CISA’s KEV catalog, suggesting no confirmed large‑scale exploits to date. An attacker would most likely need access to the WordPress backend or the ability to submit content via the plugin. Once the script is stored, every site visitor is affected, raising the potential impact to the entire user base of a site. Because the flaw is stored XSS, the risk remains high until the plugin is updated.

Generated by OpenCVE AI on October 7, 2026 at 18:34 UTC.

Remediation

Vendor Solution

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin to the latest available version (at least 2.0.20).


OpenCVE Recommended Actions

  • Update Unlimited Elements For Elementor to version 2.0.20 or later.
  • Scan for and delete any previously stored malicious content such as rogue widgets, shortcodes or custom templates that may have been injected before the upgrade.
  • For environments that cannot perform an immediate update, lock the plugin’s widget insertion to Administrator users only or temporarily disable the plugin on public pages until the update can be applied.

Generated by OpenCVE AI on October 7, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
Title WordPress Unlimited Elements For Elementor plugin <= 2.0.19 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T17:49:13.996Z

Reserved: 2026-09-22T00:19:50.790Z

Link: CVE-2026-94662

cve-icon Vulnrichment

Updated: 2026-10-07T17:49:07.523Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:03.500

Modified: 2026-10-07T18:17:31.650

Link: CVE-2026-94662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:45:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')