Unlimited-elements
Unlimited-elements Unlimited Elements FOR Elementor: vulnerabilidades y CVE
Unlimited-elements Unlimited Elements FOR Elementor tiene 48 vulnerabilidades publicadas, 25 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses25
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-105064 | Media (6.5) | 0.24% | — | 5 oct 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor… |
| CVE-2026-103355 | Crítica (9.3) | 0.25% | — | 4 oct 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)… |
| CVE-2026-103344 | Alta (7.1) | 0.15% | — | 4 oct 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)… |
| CVE-2026-103342 | Alta (7.1) | 0.15% | — | 3 oct 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)… |
| CVE-2026-92923 | Media (6.3) | 0.18% | — | 3 oct 2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL… |
| CVE-2026-85568 | Media (6.8) | 0.22% | — | 3 oct 2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection… |
| CVE-2026-85015 | Media (6.6) | 0.42% | — | 3 oct 2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature… |
| CVE-2026-92924 | Media (5.4) | 0.18% | — | 2 oct 2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have… |
| CVE-2026-85016 | Media (6.8) | 0.24% | — | 2 oct 2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor… |
| CVE-2026-103341 | Media (5.3) | 0.19% | — | 1 oct 2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control… |
| CVE-2026-103338 | Alta (8.5) | 0.21% | — | 1 oct 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)… |
| CVE-2026-85017 | Alta (7.5) | 0.40% | — | 20 sept 2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for… |
| CVE-2026-66608 | Media (6.4) | 0.23% | — | 17 sept 2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. |
| CVE-2026-77150 | Media (6.1) | 0.45% | — | 11 sept 2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization… |
| CVE-2026-18561 | Alta (7.5) | 0.33% | — | 11 sept 2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied… |
| CVE-2026-84820 | Alta (7.1) | 0.25% | — | 8 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. |
| CVE-2026-75586 | Media (6.1) | 0.38% | — | 5 sept 2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization… |
| CVE-2026-85304 | Media (5.3) | 0.31% | — | 3 sept 2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… |
| CVE-2026-28146 | Media (6.5) | 0.44% | — | 6 ago 2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. |
| CVE-2026-28147 | Media (5.4) | 0.29% | — | 3 ago 2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… |
| CVE-2026-10081 | Alta (8.8) | 0.51% | — | 20 jul 2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing… |
| CVE-2026-57718 | Alta (7.1) | 0.25% | — | 13 jul 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)… |
| CVE-2026-27041 | Crítica (9.9) | 0.48% | — | 17 jun 2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| CVE-2026-48837 | Alta (8.5) | 0.36% | — | 25 may 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor:… |
| CVE-2025-13692 | Alta (7.2) | 0.30% | — | 27 nov 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output… |
| CVE-2025-8603 | Media (6.4) | 0.24% | — | 28 ago 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output… |
| CVE-2025-1663 | Media (5.4) | 0.23% | — | 3 abr 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output… |
| CVE-2024-13155 | Media (5.4) | 0.35% | — | 20 feb 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient… |
| CVE-2024-13153 | Media (5.4) | 0.31% | — | 9 ene 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output… |
| CVE-2024-10784 | Media (5.4) | 0.35% | — | 12 dic 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.