Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor by Unlimited Elements
CVE-2026-103344

7.1HIGH

What is CVE-2026-103344?

An improper neutralization of input during web page generation allows attackers to execute reflected cross-site scripting (XSS) on users of Unlimited Elements For Elementor. This vulnerability can lead to unauthorized actions and data exposure for users visiting affected sites. Proper validation and sanitization of user inputs are crucial to mitigate risks associated with this issue.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.20

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.