CVE-2026-103344: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/unlimited-elements-for-elementorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Frequently Asked Questions
What level of access does an attacker need to attempt exploitation?
The vulnerability is remotely reachable and does not require attacker privileges. Exploitation requires user interaction, meaning a victim must be induced to interact with attacker-controlled content or a crafted request.
Which installations should be considered affected?
Installations using the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin at version 2.0.20 or earlier should be considered affected. The available data does not identify a fixed version as unaffected.