---
id: CVE-2026-95534
title: >-
  Deserialization of Untrusted Data vulnerability in Unlimited Elements
  Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows
  Object Injection.


  This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
summary: >-
  Deserialization of Untrusted Data vulnerability in Unlimited Elements
  Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows
  Object Injection.


  This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: Unlimited Elements
product: unlimited-elements-for-elementor
affected:
  - unlimited-elements-for-elementor >= n/a <= 2.0.19
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:31.777'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95534'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-19-php-object-injection-vulnerability?_s_id=cve
    label: audit@patchstack.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T17:32:01.294517Z'
ingestedAt: '2026-10-07T17:40:37.545Z'
---

## Overview

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.

This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
