PLUGIN SECURITY
Is Unlimited Elements For Elementor safe?
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
What this plugin does
- Slug:
unlimited-elements-for-elementor - Author: Unlimited Elements
- 300000+ active installs
- 96/100 rating (521 reviews on wordpress.org)
- 15802280 all-time downloads
- On WordPress.org since 2018-02-01
elementorelementor addonselementor templateselementor widgetswidgets for elementor
Maintenance status
- Latest known version: 2.0.16
- Last updated: 2026-08-24 12:13pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
40 known CVEs on file for Unlimited Elements For Elementor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-85304 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.18 | Missing Authorization | Medium 5.3 | < 2.0.18 | 2.0.18 | 2026-09-03 | ⚠ update needed |
| CVE-2026-28147 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.16 | Missing Authorization | Medium 5.4 | < 2.0.16 | 2.0.16 | 2026-08-03 | ✓ fixed in latest |
| CVE-2026-28146 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.15 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 2.0.15 | 2.0.15 | 2026-08-03 | ✓ fixed in latest |
| CVE-2026-57718 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.13 | — | High 7.1 | < 2.0.13 | 2.0.13 | 2026-07-09 | ✓ fixed in latest |
| CVE-2026-10081 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.0.11 | 2.0.11 | 2026-06-29 | ✓ fixed in latest |
| CVE-2026-48837 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 2.0.9 | 2.0.9 | 2026-05-25 | ✓ fixed in latest |
| CVE-2026-5486 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 2.0.8 | 2.0.8 | 2026-05-13 | ✓ fixed in latest |
| CVE-2024-13362 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.5.141 | 1.5.141 | 2026-04-30 | ✓ fixed in latest |
+ 40 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-4659 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.7 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 2.0.7 | 2.0.7 | 2026-04-16 | ✓ fixed in latest |
| CVE-2025-14274 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.0.2 | 2.0.2 | 2026-02-02 | ✓ fixed in latest |
| CVE-2025-13692 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.0.1 | 2.0.1 | 2025-11-26 | ✓ fixed in latest |
| CVE-2024-13155 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.5.141 | 1.5.141 | 2025-02-19 | ✓ fixed in latest |
| CVE-2024-13153 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.136 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.5.136 | 1.5.136 | 2025-01-08 | ✓ fixed in latest |
| CVE-2024-10784 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.127 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.5.127 | 1.5.127 | 2024-12-11 | ✓ fixed in latest |
| CVE-2024-49271 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 | Improper Neutralization of Script in Attributes of IMG Tags in a Web Page | Critical 9.1 | < 1.5.122 | 1.5.122 | 2024-10-14 | ✓ fixed in latest |
| CVE-2024-45454 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.5.122 | 1.5.122 | 2024-09-30 | ✓ fixed in latest |
| CVE-2024-6170 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.5.113 | 1.5.113 | 2024-07-08 | ✓ fixed in latest |
| CVE-2024-6169 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.5.113 | 1.5.113 | 2024-07-08 | ✓ fixed in latest |
| CVE-2024-6171 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 | Use of Less Trusted Source | Medium 5.3 | < 1.5.113 | 1.5.113 | 2024-07-08 | ✓ fixed in latest |
| CVE-2024-6166 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.5.113 | 1.5.113 | 2024-07-08 | ✓ fixed in latest |
| CVE-2024-35674 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 | Missing Authorization | Medium 4.3 | < 1.5.110 | 1.5.110 | 2024-06-05 | ✓ fixed in latest |
| CVE-2024-5329 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.5.110 | 1.5.110 | 2024-06-05 | ✓ fixed in latest |
| CVE-2024-3190 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.6 | < 1.5.108 | 1.5.108 | 2024-05-29 | ✓ fixed in latest |
| CVE-2023-6743 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.91 | Improper Control of Generation of Code ('Code Injection') | High 8.8 | < 1.5.91 | 1.5.91 | 2024-05-28 | ✓ fixed in latest |
| CVE-2024-4779 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.5.108 | 1.5.108 | 2024-05-22 | ✓ fixed in latest |
| CVE-2024-3055 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.5.105 | 1.5.105 | 2024-05-10 | ✓ fixed in latest |
| CVE-2024-2662 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | High 7.2 | < 1.5.103 | 1.5.103 | 2024-05-09 | ✓ fixed in latest |
| CVE-2024-3547 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.5.103 | 1.5.103 | 2024-05-09 | ✓ fixed in latest |
| CVE-2024-0367 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.97 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.5.97 | 1.5.97 | 2024-03-29 | ✓ fixed in latest |
| CVE-2024-29792 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.5.94 | 1.5.94 | 2024-03-25 | ✓ fixed in latest |
| CVE-2023-33999 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.75 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.5.75 | 1.5.75 | 2023-07-18 | ✓ fixed in latest |
| CVE-2023-31080 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 | Missing Authorization | High 8.3 | < 1.5.66 | 1.5.66 | 2023-06-20 | ✓ fixed in latest |
| CVE-2023-31231 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 | Unrestricted Upload of File with Dangerous Type | Critical 9.9 | < 1.5.66 | 1.5.66 | 2023-06-20 | ✓ fixed in latest |
| CVE-2023-3295 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 1.5.67 | 1.5.67 | 2023-06-16 | ✓ fixed in latest |
| CVE-2023-31090 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.61 | Unrestricted Upload of File with Dangerous Type | Critical 9.9 | < 1.5.61 | 1.5.61 | 2023-05-22 | ✓ fixed in latest |
| CVE-2023-33930 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 | Unrestricted Upload of File with Dangerous Type | Critical 9.1 | < 1.5.67 | 1.5.67 | 2023-05-22 | ✓ fixed in latest |
| CVE-2022-47170 | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.49 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 1.5.49 | 1.5.49 | 2023-01-27 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 | Missing Authorization | Medium 6.3 | < 1.5.3 | 1.5.3 | 2022-03-04 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | 2022-02-28 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | 2022-02-28 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.143 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.5.143 | 1.5.143 | 0000-00-00 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.149 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.5.149 | 1.5.149 | 0000-00-00 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.6 | — | Unknown | < 2.0.6 | 2.0.6 | 0000-00-00 | ✓ fixed in latest |
| — | Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | — | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 1.5.3 | 1.5.3 | — | ✓ fixed in latest |
| CVE-2025-1663 | Unlimited Elements For Elementor < 1.5.143 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 1.5.143 | 1.5.143 | — | ✓ fixed in latest |
| CVE-2025-8603 | Unlimited Elements For Elementor < 1.5.149 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 1.5.149 | 1.5.149 | — | ✓ fixed in latest |
| CVE-2026-2724 | Unlimited Elements For Elementor < 2.0.6 - Unauthenticated Stored Cross-Site Scripting | — | Unknown | < 2.0.6 | 2.0.6 | — | ✓ fixed in latest |
How to fix it
Keep Unlimited Elements For Elementor updated — 2.0.16 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7297)
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Essential Addons for Elementor – Popular Elementor Templates & Widgets — 1000000+ active installs — 98/100 (4113) — max PHP 8.4
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg — 1000000+ active installs — 98/100 (4745) — max PHP 8.4
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor — 1000000+ active installs — 98/100 (2036) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.