CVE-2026-85016None▾ SunlitThe Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77150Medium· 6.1The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping.…
CVE-2026-92924Medium· 5.4Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data
CVE-2026-85017High· 7.5The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers wi…
CVE-2026-18561High· 7.5Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library