CVE Database /
CVE-2026-28147
CVE · Medium
CVE-2026-28147 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-28147
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.16 |
Missing Authorization |
Medium
5.4
|
< 2.0.16
|
2.0.16 |
2026-08-03 |
—
|
CVE-2026-28147
A critical security flaw exists in the access control mechanism of Unlimited Elements For Elementor plugin, allowing unauthorized users to bypass configured security settings and gain unintended access. This vulnerability is present in versions up to 2.0.15 of the plugin, which includes free widgets, addons, and templates for Elementor.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings