CVE-2026-77150: Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting

Published Sep 11, 2026
·
Updated

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The showpreview AJAX action is registered for unauthenticated users and is gated only by a nonce, which an unauthenticated attacker can retrieve by loading any publicly accessible page that emits it.

Affected Software

1 affected component
Elementor Unlimited Elements For Elementor<=2.0.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: Unlimited Elements For Elementor to a version that resolves this vulnerability.

    Fixed in 2.0.16

Event History

Sep 11, 2026
CVE Published
via MITRE·03:39 AM
Data Sourced
via MITRE·03:39 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Sites running Unlimited Elements For Elementor version 2.0.16 or earlier are affected. An attacker does not need an account, but successful exploitation requires a user to be induced to interact with a crafted link or similar request.

2

Does the issue affect publicly accessible sites by default?

The vulnerable show_preview AJAX action is available to unauthenticated users. Its nonce check is not an effective access barrier when an attacker can load a publicly accessible page that emits the nonce.

3

What can be done if patching is not immediately possible?

The provided information does not identify a configuration-only mitigation. Reduce exposure by preventing public access to pages that emit the required nonce where feasible, and warn users not to follow untrusted links to the site until remediation is available.

4

How can I determine whether my site is affected?

Check whether Unlimited Elements For Elementor is installed and whether its version is 2.0.16 or earlier. Also determine whether unauthenticated visitors can access pages that emit the nonce used by the show_preview AJAX action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203