CVE-2026-95534: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - PHP Object Injection vulnerability
Published Oct 7, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
Affected Software
1 affected component
Unlimited Elements Unlimited Elements For Elementor<=2.0.19
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)to a version that resolves this vulnerability.Fixed in 2.0.20
Event History
Oct 7, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack is network-accessible and requires low privileges. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
The reported CVSS vector indicates high impact to confidentiality, integrity, and availability.