---
id: CVE-2026-77150
title: >-
  The Unlimited Elements For Elementor plugin for WordPress is vulnerable to
  Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up
  to, and including, 2.0.16 due to insufficient input sanitization and output
  escaping.…
summary: >-
  The Unlimited Elements For Elementor plugin for WordPress is vulnerable to
  Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up
  to, and including, 2.0.16 due to insufficient input sanitization and output
  escaping.…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: unitecms
product: Unlimited Elements For Elementor
affected:
  - unlimited_elements_for_elementor <= 2.0.16
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:19:10.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77150'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/functions.php#L53
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L379
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L42
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addon.class.php#L272
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php#L1437
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_operations.class.php#L212
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_admin.class.php#L305
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3661670%40unlimited-elements-for-elementor%2Ftrunk&old=3628543%40unlimited-elements-for-elementor%2Ftrunk&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/3deeb8f5-d9a7-43cb-9068-a921ed6db2bc?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T16:43:52.287483Z'
epss: 0.00254
epssPercentile: 0.17213
ingestedAt: '2026-09-11T16:45:47.927Z'
---

## Overview

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The show_preview AJAX action is registered for unauthenticated users and is gated only by a nonce, which an unauthenticated attacker can retrieve by loading any publicly accessible page that emits it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
