Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor
CVE-2026-57718

7.1HIGH

What is CVE-2026-57718?

The Unlimited Elements for Elementor plugin, which provides free widgets, addons, and templates, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This issue arises from the improper neutralization of input during the web page generation process, allowing attackers to execute arbitrary scripts in users' browsers. Its impact can lead to session hijacking, data theft, and website defacement. This vulnerability affects versions up to 2.0.12, highlighting the importance of updating to secure against potential exploits.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.12

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Taylsec | Patchstack Bug Bounty Program
.