CVE-2026-105064: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.22 - Broken Access Control vulnerability
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.22.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/unlimited-elements-for-elementorto a version that resolves this vulnerability.Fixed in 2.0.23
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack vector is network-accessible and requires low privileges. No user interaction is required.
What is the potential impact if the vulnerability is exploited?
The vulnerability has high confidentiality impact. The supplied metrics indicate no integrity or availability impact.
Which plugin versions are affected?
Affected versions are listed as through 2.0.22. The affected version range does not specify a known lower bound.