Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor by Unlimited Elements
CVE-2026-103342

7.1HIGH

What is CVE-2026-103342?

The Unlimited Elements for Elementor plugin experiences a vulnerability due to improper neutralization of user input during web page generation. This flaw allows attackers to execute arbitrary JavaScript code in the browser of users visiting affected pages. Consequently, the attacker could manipulate content or perform malicious actions within the context of the victim's session, potentially leading to unauthorized access to sensitive information.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.20

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.