SecAlerts
u

unlimited elements

Security Risk Profile

55
/100
medium

Security Risk Score

Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 27, 2024 to present

22
Total CVEs
13
Critical+High
0
Exploited
6
Unpatched

Threat Assessment

Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
55/100
medium

Severity Distribution

Critical
4
High
9
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
11
2
SQL Injection
4
3
Malicious File Upload
3
4
Code Injection
3
5
Command Injection
2

Most Affected Products

1. Unlimited Elements Unlimited Elements For Elementor16
2. unlimited-elements Unlimited Elements For Elementor Wordpress16
3. Unlimited Elements For Elementor5
4. WordPress Unlimited Elements For Elementor3
5. WordPress Unlimited Elements for Elementor plugin2

Recent Vulnerabilities

See more →
CVE-2026-27041
CVSS 9.9critical

WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitrary File Upload vulnerability

Jun 17, 2026🔧 No Patch
CVE-2026-48837
CVSS 8.5high

WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vulnerability

May 25, 2026🔧 No Patch
CVE-2026-5486
CVSS 6.5medium

Unlimited Elements For Elementor <= 2.0.7 - Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter

May 14, 2026🔧 No Patch
CVE-2026-4659
CVSS 7.5high

Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal

Apr 17, 2026🔧 No Patch
CVE-2025-13692
CVSS 7.2high

Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) <= 2.0 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

Nov 27, 2025🔧 No Patch
CVE-2025-8603
CVSS 6.4EPSS 0%medium

Unlimited Elements For Elementor <= 1.5.148 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 28, 2025🔧 No Patch
CVE-2025-1663
CVSS 6.4medium

Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 3, 2025
CVE-2024-13155
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget

Feb 20, 2025🔧 No Patch
CVE-2024-13153
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Jan 9, 2025🔧 No Patch
CVE-2024-10784
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2024

Monitor unlimited elements in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

unlimited elements Security Vulnerabilities & Risk Score | 22 CVEs | SecAlerts - SecAlerts