Extension WordPress

Vulnérabilités Unlimited Elements For Elementor

Cette page rassemble les failles publiées pour Unlimited Elements For Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

36Vulnérabilités
2Critiques
36Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Unlimited Elements For Elementor

36 fiches

CVE-2026-57718 Élevée · 7,2
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 2.0.12 – Unauthenticated Stored Cross-Site Scripting

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-2.0.12

Correctif

2.0.13

Publication

09/07/2026

CVE-2026-5486 Moyenne · 6,5
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 2.0.7 – Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the…

Versions affectées

*-2.0.7

Correctif

2.0.8

Publication

13/05/2026

CVE-2024-13362 Moyenne · 6,1
Unlimited Elements For Elementor

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.5.140

Correctif

1.5.141

Publication

30/04/2026

CVE-2026-4659 Élevée · 7,5
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 2.0.6 – Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative()…

Versions affectées

*-2.0.6

Correctif

2.0.7

Publication

16/04/2026

CVE-2026-2724 Élevée · 7,2
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 2.0.5 – Unauthenticated Stored Cross-Site Scripting via Form Entry Fields

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.0.5

Correctif

2.0.6

Publication

09/03/2026

CVE-2025-14274 Moyenne · 5,4
Unlimited Elements For Elementor

Unlimited Elements for Elementor <= 2.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.0.1

Correctif

2.0.2

Publication

02/02/2026

CVE-2025-13692 Élevée · 7,2
Unlimited Elements For Elementor

Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) <= 2.0 – Unauthenticated Stored Cross-Site Scripting via SVG File Upload

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.0

Correctif

2.0.1

Publication

26/11/2025

CVE-2025-8603 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 1.5.148 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.5.148

Correctif

1.5.149

Publication

27/08/2025

CVE-2025-1663 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor <= 1.5.142 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.5.142

Correctif

1.5.143

Publication

02/04/2025

CVE-2024-13155 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 – Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on…

Versions affectées

*-1.5.140

Correctif

1.5.141

Publication

19/02/2025

CVE-2024-13153 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-1.5.135

Correctif

1.5.136

Publication

08/01/2025

CVE-2024-10784 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output…

Versions affectées

*-1.5.126

Correctif

1.5.127

Publication

11/12/2024

CVE-2024-49271 Élevée · 7,2
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.121 – Authenticated (Editor+) Remote Code Execution

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.121 via the template engine. This is due to the plugin not properly…

Versions affectées

*-1.5.121

Correctif

1.5.122

Publication

14/10/2024

CVE-2024-45454 Moyenne · 6,1
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.121 – Reflected Cross-Site Scripting

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.121 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.5.121

Correctif

1.5.122

Publication

30/09/2024

CVE-2024-6169 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'username'

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.5.112

Correctif

1.5.113

Publication

08/07/2024

CVE-2024-6170 Moyenne · 6,4
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'email'

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.5.112

Correctif

1.5.113

Publication

08/07/2024

CVE-2024-6166 Élevée · 8,8
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 – Authenticated (Contributor+) Time-Based SQL Injection

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied…

Versions affectées

*-1.5.112

Correctif

1.5.113

Publication

08/07/2024

CVE-2024-6171 Moyenne · 5,3
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 – IP Address Spoofing to Antispam Bypass

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers…

Versions affectées

*-1.5.112

Correctif

1.5.113

Publication

08/07/2024

CVE-2024-5329 Élevée · 8,8
Unlimited Elements For Elementor

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 – Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied…

Versions affectées

*-1.5.109

Correctif

1.5.110

Publication

05/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités