CVE · Medium

CVE-2025-14274 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14274 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.0.2 2.0.2 2026-02-02

CVE-2025-14274

The Unlimited Elements plugin for Elementor has a security flaw affecting versions up to 2.0.1. The issue arises from inadequate filtering of URLs entered into the Button Link field within the Border Hero widget, allowing malicious actors with access levels of Contributor or higher to embed unauthorized scripts that will run when users visit affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.