Missing Authorization Vulnerability in Unlimited Elements for Elementor by Patchstack
CVE-2026-85304

5.3MEDIUM

What is CVE-2026-85304?

A vulnerability in Unlimited Elements For Elementor, specifically in versions up to 2.0.17, allows unauthorized access due to incorrectly configured access control security levels. This missing authorization issue could potentially enable attackers to exploit the plugin, compromising security measures set in place, and exposing sensitive functionalities or data. It is critical for users of the plugin to ensure proper configuration and apply any available updates to safeguard their sites.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Johan Buenavida | Patchstack Bug Bounty Program
.