CVE-2024-13153
The Unlimited Elements For Elementor plugin contains a stored cross-site scripting vulnerability affecting versions up to 1.5.135 in multiple widgets including Image Tooltip, Notification, Simple Popup, Video Play Button, and Card Carousel. Authenticated users with contributor-level permissions or higher can inject malicious scripts through insufficiently sanitized widget attributes, causing the code to execute for any visitor viewing the affected pages. The vulnerability stems from inadequate input validation and output encoding of user-supplied data. To resolve this issue, the vulnerable widgets must be manually removed and reinstalled since they are not part of the main plugin codebase.
Based on public CVE data (MITRE/NVD).