Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor by Unlimited Elements
CVE-2026-103344
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 October 2026
What is CVE-2026-103344?
An improper neutralization of input during web page generation allows attackers to execute reflected cross-site scripting (XSS) on users of Unlimited Elements For Elementor. This vulnerability can lead to unauthorized actions and data exposure for users visiting affected sites. Proper validation and sanitization of user inputs are crucial to mitigate risks associated with this issue.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.20