CVE-2026-103342: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
unlimited-elements-for-elementorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Frequently Asked Questions
Which installations are affected?
Installations running Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions through 2.0.20 are affected.
Does exploitation require an authenticated WordPress account?
No. The CVSS vector indicates no privileges are required, and the issue is remotely reachable over the network. Exploitation does require user interaction.