CVE-2026-28147: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates)to a version that resolves this vulnerability.Fixed in 2.0.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28147?
The severity of CVE-2026-28147 is medium, with a score of 5.4.
How do I fix CVE-2026-28147?
To fix CVE-2026-28147, update the Unlimited Elements For Elementor plugin to version 2.0.16 or later.
What type of vulnerability is CVE-2026-28147?
CVE-2026-28147 is a Broken Access Control vulnerability.
Who is affected by CVE-2026-28147?
Any users of the Unlimited Elements For Elementor plugin version 2.0.15 or earlier are affected by CVE-2026-28147.
How does CVE-2026-28147 affect WordPress security?
CVE-2026-28147 allows attackers to exploit incorrectly configured access control security levels, potentially compromising user data.