CVE Database /
CVE-2025-14274
CVE · Medium
CVE-2025-14274 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14274
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.0.2
|
2.0.2 |
2026-02-02 |
—
|
CVE-2025-14274
The Unlimited Elements plugin for Elementor has a security flaw affecting versions up to 2.0.1. The issue arises from inadequate filtering of URLs entered into the Button Link field within the Border Hero widget, allowing malicious actors with access levels of Contributor or higher to embed unauthorized scripts that will run when users visit affected pages.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings