Cross-site Scripting in Unlimited Elements For Elementor by Unlimited Elements
CVE-2026-94662

7.1HIGH

What is CVE-2026-94662?

A Cross-site Scripting vulnerability exists in Unlimited Elements For Elementor, which allows attackers to inject malicious scripts into web pages. This vulnerability can lead to Stored XSS attacks, where an attacker’s script executes in the context of other users’ browsers, potentially compromising their data and sessions. This issue is prevalent in versions up to 2.0.19, making it essential for users to update their plugins to safeguard against such threats.

Affected Version(s)

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ayukiab | Patchstack Bug Bounty Program
.