WordPress · Unlimited Elements For Elementor · CVE-2026-105064
**Name of the Vulnerable Software and Affected Versions**
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions prior to 2.0.23
**Description**
An Unsafe Reflection issue exists where the software uses externally-controlled input to select classes or code, leading to Parameter Injection. This occurs when the application allows user-supplied data to influence the reflection process, which is a mechanism used to inspect or modify the runtime behavior of applications.
**Recommendations**
Update Unlimited Elements For Elementor (Free Widgets, Addons, Templates) to version 2.0.23 or later.