CVE-2026-85304: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.17 - Broken Access Control vulnerability
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) pluginto a version that resolves this vulnerability.Fixed in 2.0.18
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed over the network with no privileges and no user interaction required. The disclosed impact is limited to confidentiality; integrity and availability impacts are not indicated.
Which installations should be considered affected?
Installations using Unlimited Elements For Elementor (Free Widgets, Addons, Templates) through version 2.0.17 are affected according to the disclosure. The affected version range does not identify a lower bound.