📦 Unlimited Elements For Elementor

by Unlimited Elements

🔍 What is Unlimited Elements For Elementor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33930

CRITICAL CVSS 9.1 Jun 4, 2024

This vulnerability allows attackers to upload malicious ZIP files containing dangerous file types to WordPress sites using the Unlimited Elements for Elementor plugin. When extracted, these files can ...

CVE-2023-31090

CRITICAL CVSS 9.9 Apr 24, 2024

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the Unlimited Elements for Elementor plugin. Attackers can achieve remote code execution...

CVE-2024-45454

HIGH CVSS 7.1 Oct 6, 2024

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the Unlimited Elements for Elementor WordPress plugin. Attackers can inject malicious scripts via crafted URLs that execute w...

CVE-2023-31080

HIGH CVSS 8.3 Jun 9, 2024

This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows attackers to perform unauthorized actions due to broken access controls. Al...

CVE-2024-5329

HIGH CVSS 8.8 Jun 6, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform blind SQL injection attacks via the 'data[addonID]' parameter in the Unlimited Elements For E...

CVE-2023-6743

HIGH CVSS 8.8 May 29, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to execute arbitrary code on the server through the Unlimited Elements For Elementor plugin's template i...

CVE-2024-4779

HIGH CVSS 8.8 May 23, 2024

This vulnerability allows authenticated attackers with contributor-level access or higher to perform SQL injection attacks via the 'data[post_ids][0]' parameter in the Unlimited Elements For Elementor...

CVE-2024-3055

HIGH CVSS 8.8 May 14, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to perform time-based SQL injection attacks through the 'id' parameter in the Unlimited Elements For Ele...

CVE-2024-2662

HIGH CVSS 7.2 May 14, 2024

This vulnerability allows authenticated WordPress administrators to execute arbitrary commands on the server through the Unlimited Elements For Elementor plugin. Attackers with admin access can inject...

CVE-2024-29792

HIGH CVSS 7.1 Mar 27, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Unlimited Elements For Elementor WordPress plugin. When users visit a specially crafted URL, the scripts...

CVE-2023-3295

HIGH CVSS 8.8 Jun 17, 2023

This vulnerability in the Unlimited Elements For Elementor WordPress plugin allows authenticated attackers with contributor-level permissions or higher to upload arbitrary files due to missing file ty...

CVE-2024-13155

MEDIUM CVSS 6.4 Feb 20, 2025

The Unlimited Elements For Elementor WordPress plugin has a stored XSS vulnerability in its Transparent Split Hero widget. Authenticated attackers with contributor-level access or higher can inject ma...

CVE-2024-10784

MEDIUM CVSS 6.4 Dec 12, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pages using the Unlimited Elements for Elementor plugin's Tile Gallery ...

CVE-2024-35674

MEDIUM CVSS 4.3 Jun 5, 2024

This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows unauthorized users to access functionality intended only for authenticated ...

CVE-2022-47170

MEDIUM CVSS 5.9 Mar 28, 2023

This vulnerability allows authenticated administrators to inject malicious scripts into the Unlimited Elements for Elementor WordPress plugin. When other users view pages containing these injected scr...