CVE Database /
CVE-2024-49271
CVE · Critical
CVE-2024-49271 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-49271
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 |
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page |
Critical
9.1
|
< 1.5.122
|
1.5.122 |
2024-10-14 |
—
|
CVE-2024-49271
The Unlimited Elements For Elementor plugin contains a remote code execution vulnerability affecting versions up to 1.5.121 through its template engine. The plugin fails to adequately limit which functions can be invoked when passed to code execution functions, allowing authenticated users with Editor role or higher to run arbitrary code on the server. This vulnerability has been resolved in version 1.5.122 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings