Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor by Unlimited Elements
CVE-2026-103342
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-103342?
The Unlimited Elements for Elementor plugin experiences a vulnerability due to improper neutralization of user input during web page generation. This flaw allows attackers to execute arbitrary JavaScript code in the browser of users visiting affected pages. Consequently, the attacker could manipulate content or perform malicious actions within the context of the victim's session, potentially leading to unauthorized access to sensitive information.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.20