SecAlerts
u

unlimited-elements

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 27 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 28, 2023 to present

27
Total CVEs
16
Critical+High
0
Exploited
6
Unpatched

Threat Assessment

Avg CVSS
7.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
45/100
medium

Severity Distribution

Critical
4
High
12
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
XSS
12
2
SQL Injection
4
3
Malicious File Upload
4
4
Code Injection
3
5
Command Injection
2

Most Affected Products

1. unlimited-elements Unlimited Elements For Elementor Wordpress22
2. Unlimited Elements Unlimited Elements For Elementor12
3. unlimited-elements Unlimited Elements For Elementor \(free Widgets\, Addons\, Templates\) Wordpress6
4. Unlimited Elements For Elementor4
5. WordPress Unlimited Elements For Elementor3

Recent Vulnerabilities

See more →
CVE-2025-1663
CVSS 6.4medium

Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 3, 2025
CVE-2024-13155
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget

Feb 20, 2025🔧 No Patch
CVE-2024-13153
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Jan 9, 2025🔧 No Patch
CVE-2024-10784
CVSS 6.4medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2024
CVE-2024-49271
CVSS 9.1EPSS 2%critical

WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability

Oct 16, 2024
CVE-2024-45454
CVSS 7.1high

WordPress Unlimited Elements for Elementor plugin <= 1.5.121 - Reflected Cross Site Scripting (XSS) vulnerability

Oct 6, 2024
CVE-2024-6169
CVSS 6.4EPSS 0%medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'username'

Jul 9, 2024🔧 No Patch
CVE-2024-6170
CVSS 6.4EPSS 0%medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'email'

Jul 9, 2024🔧 No Patch
CVE-2024-6166
CVSS 8.8EPSS 0%high

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injection

Jul 9, 2024🔧 No Patch
CVE-2024-6171
CVSS 5.3EPSS 0%medium

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass

Jul 9, 2024🔧 No Patch

Monitor unlimited-elements in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.