Reflected Cross-Site Scripting in Unlimited Elements For Elementor Plugin
CVE-2026-75586

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2026

What is CVE-2026-75586?

The Unlimited Elements For Elementor plugin for WordPress is susceptible to reflected cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping. An attacker can exploit this through the 'formData[id]' parameter found in AJAX requests, allowing them to inject malicious scripts into web pages. This poses a significant risk as an unauthenticated attacker can deceive users into clicking a crafted link, thereby executing the injected scripts in their browsers. The lack of security measures, such as nonce, capability, or referer checks on the AJAX handler, exacerbates the vulnerability, making it possible for raw attacker-controlled values to be displayed in responses served as text/html.

Affected Version(s)

Unlimited Elements For Elementor 0 <= 2.0.17

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuto Hyakumoto
.