Server Side Request Forgery in Unlimited Elements for Elementor Plugin
CVE-2026-66608

6.4MEDIUM

What is CVE-2026-66608?

The Unlimited Elements for Elementor plugin, specifically versions up to 2.0.19, has a sensitivity to Server Side Request Forgery (SSRF). This vulnerability allows unauthorized users to send crafted requests to internal services within the hosting server, leading to potential data exposure and manipulation. Users of this plugin are advised to check their versions and apply necessary updates to mitigate any risks associated with this security flaw.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ayukiab | Patchstack Bug Bounty Program
.