Arbitrary File Download Vulnerability in Unlimited Elements for Elementor by Patchstack
CVE-2026-28146

6.5MEDIUM

What is CVE-2026-28146?

The Unlimited Elements for Elementor plugin, specifically versions up to 2.0.14, contains a significant vulnerability that allows unauthenticated attackers to exploit an arbitrary file download flaw. This could potentially expose sensitive files on the server, leading to significant security risks. Website administrators are strongly advised to update to a newer version to mitigate this vulnerability.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TurboNexic | Patchstack Bug Bounty Program
.