• Resolved pengie5696

    (@pengie5696)


    Per WordFence, issue found 13 Feb 2026 – marked as critical issue recommending removing the plugin till patched.

    • Plugin Name: Unlimited Elements for Elementor
    • Current Plugin Version: 2.0.1
    • Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Unlimited Elements for Elementor” until a patched version is available. Get more information.(opens in new tab)
    • Vulnerability Severity: 5.4/10.0 (Medium)

    If a patch is forthcoming, I’ll keep the plugin installed to eliminate a disruption on the client website… While marked as “critical” — the vulnerability severity score is medium. Hope you can patch it though ASAP.

    WordFence cites the following:

    The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget’s Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page

    TIA!

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.