Cross-site Scripting in Unlimited Elements For Elementor by Unlimited Elements
CVE-2026-94662
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-94662?
A Cross-site Scripting vulnerability exists in Unlimited Elements For Elementor, which allows attackers to inject malicious scripts into web pages. This vulnerability can lead to Stored XSS attacks, where an attacker’s script executes in the context of other users’ browsers, potentially compromising their data and sessions. This issue is prevalent in versions up to 2.0.19, making it essential for users to update their plugins to safeguard against such threats.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19