PT-2026-104585 · WordPress · Unlimited Elements For Elementor

CVE-2026-103342

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions prior to 2.0.21
Description An issue involving improper neutralization of input during web page generation allows for Reflected Cross-site Scripting (XSS), a technique where malicious scripts are injected into trusted websites and executed in the user's browser.
Recommendations Update Unlimited Elements For Elementor (Free Widgets, Addons, Templates) to version 2.0.21 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103342

Affected Products

Unlimited Elements For Elementor