CVE-2026-27041: WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitrary File Upload vulnerability
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If you cannot immediately apply an available vendor fix, deactivate or uninstall the 'Unlimited Elements for Elementor (Premium)' WordPress plugin, or otherwise prevent contributor-role users from uploading files (e.g., via capability restrictions or a plugin that blocks uploads) until a patched version is installed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27041?
The severity of CVE-2026-27041 is rated as critical with a score of 9.9.
How do I fix CVE-2026-27041?
To fix CVE-2026-27041, update the Unlimited Elements for Elementor (Premium) plugin to version 2.0.7 or later.
What type of vulnerability is CVE-2026-27041?
CVE-2026-27041 is classified as an Arbitrary File Upload vulnerability.
Which software is affected by CVE-2026-27041?
CVE-2026-27041 affects the Unlimited Elements for Elementor (Premium) plugin versions 2.0.6 and below.
What impact does CVE-2026-27041 have on security?
CVE-2026-27041 can allow attackers to upload malicious files, potentially leading to further compromise of the website.