Reflected Cross-Site Scripting in Unlimited Elements For Elementor Plugin
CVE-2026-75586
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-75586?
The Unlimited Elements For Elementor plugin for WordPress is susceptible to reflected cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping. An attacker can exploit this through the 'formData[id]' parameter found in AJAX requests, allowing them to inject malicious scripts into web pages. This poses a significant risk as an unauthenticated attacker can deceive users into clicking a crafted link, thereby executing the injected scripts in their browsers. The lack of security measures, such as nonce, capability, or referer checks on the AJAX handler, exacerbates the vulnerability, making it possible for raw attacker-controlled values to be displayed in responses served as text/html.
Affected Version(s)
Unlimited Elements For Elementor 0 <= 2.0.17