Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter
CVE-2026-85016
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-85016?
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
Affected Version(s)
Unlimited Elements for Elementor 0 < 2.0.21
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.