---
id: CVE-2026-85016
title: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  escape an icon value before concatenating it into an HTML attribute in its
  shared widget-parameter processor, allowing users with Contributor access (who
  do not…
summary: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  escape an icon value before concatenating it into an HTML attribute in its
  shared widget-parameter processor, allowing users with Contributor access (who
  do not…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Unlimited Elements for Elementor
affected:
  - unlimited_elements_for_elementor < 2.0.21
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:00:34.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85016'
references:
  - url: 'https://wpscan.com/vulnerability/1d488c84-2797-4c02-8c13-54b80e4128dc/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00152
epssPercentile: 0.03745
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-02T10:45:54.923307Z'
ingestedAt: '2026-10-02T06:11:20.487Z'
---

## Overview

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
