Cross-Site Scripting Vulnerability in Unlimited Elements for Elementor
CVE-2026-57718
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 July 2026
What is CVE-2026-57718?
The Unlimited Elements for Elementor plugin, which provides free widgets, addons, and templates, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This issue arises from the improper neutralization of input during the web page generation process, allowing attackers to execute arbitrary scripts in users' browsers. Its impact can lead to session hijacking, data theft, and website defacement. This vulnerability affects versions up to 2.0.12, highlighting the importance of updating to secure against potential exploits.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.12