Missing Authorization Vulnerability in Unlimited Elements for Elementor by Unlimited Elements
CVE-2026-28147
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-28147?
A missing authorization vulnerability in Unlimited Elements For Elementor allows attackers to exploit incorrectly configured access controls, potentially leading to unauthorized actions within the plugin. This vulnerability affects versions of Unlimited Elements prior to 2.0.15, posing a risk to users who have not applied the latest updates.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.15