Security Threat – need a patch ASAP please
-
Per WordFence, issue found 13 Feb 2026 – marked as critical issue recommending removing the plugin till patched.
- Plugin Name: Unlimited Elements for Elementor
- Current Plugin Version: 2.0.1
- Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Unlimited Elements for Elementor” until a patched version is available. Get more information.(opens in new tab)
- Vulnerability Severity: 5.4/10.0 (Medium)
If a patch is forthcoming, I’ll keep the plugin installed to eliminate a disruption on the client website… While marked as “critical” — the vulnerability severity score is medium. Hope you can patch it though ASAP.
WordFence cites the following:
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget’s Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page
TIA!
You must be logged in to reply to this topic.