Server Side Request Forgery in Unlimited Elements for Elementor Plugin
CVE-2026-66608
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-66608?
The Unlimited Elements for Elementor plugin, specifically versions up to 2.0.19, has a sensitivity to Server Side Request Forgery (SSRF). This vulnerability allows unauthorized users to send crafted requests to internal services within the hosting server, leading to potential data exposure and manipulation. Users of this plugin are advised to check their versions and apply necessary updates to mitigate any risks associated with this security flaw.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19