SecAlerts
u

unlimited elements

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 27, 2024 to present

29
Total CVEs
14
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
7.4
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
7
Critical/High
Risk Level
52/100
medium
🆕 7Fresh (<7d)📈 7 in Last 30 Days

Severity Distribution

Critical
4
High
10
Medium
12
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
12
2
SQL Injection
7
3
Malicious File Upload
3
4
Code Injection
3
5
Path Traversal
2

Most Affected Products

1. Unlimited Elements Unlimited Elements For Elementor20
2. unlimited-elements Unlimited Elements For Elementor Wordpress16
3. Unlimited Elements For Elementor5
4. WordPress Unlimited Elements For Elementor3
5. Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)2

Recent Vulnerabilities

See more →
CVE-2026-92923
unknown

Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data

Oct 3, 2026🔧 No Patch
CVE-2026-85015
unknown

Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal

Oct 3, 2026🔧 No Patch
CVE-2026-85568
unknown

Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter

Oct 3, 2026🔧 No Patch
CVE-2026-92924
CVSS 5.4medium

Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data

Oct 2, 2026🔧 No Patch
CVE-2026-85016
CVSS 6.8medium

Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter

Oct 2, 2026🔧 No Patch
CVE-2026-103341
CVSS 5.3medium

WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Broken Access Control vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-103338
CVSS 8.5high

WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-27041
CVSS 9.9critical

WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitrary File Upload vulnerability

Jun 17, 2026🔧 No Patch
CVE-2026-48837
CVSS 8.5high

WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vulnerability

May 25, 2026🔧 No Patch
CVE-2026-5486
CVSS 6.5medium

Unlimited Elements For Elementor <= 2.0.7 - Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter

May 14, 2026🔧 No Patch

Monitor unlimited elements in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.