CVE-2026-66608: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - Server Side Request Forgery (SSRF) vulnerability
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) pluginto a version that resolves this vulnerability.Fixed in 2.0.20
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker needs Contributor-level access to exploit this issue. It does not require user interaction, and the attack can be performed over the network.
Which installations are affected?
The affected product is the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin. Versions up to and including 2.0.19 are affected.
What security impact can successful exploitation have?
The vulnerability can cause the server to make attacker-influenced requests, consistent with SSRF. The supplied vector indicates low-impact confidentiality and integrity effects, with no availability impact.