WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Unlimited Elements For Elementor safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Unlimited Elements For Elementor WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: unlimited-elements-for-elementor

Maintenance status

Known vulnerabilities

37 known CVEs on file for Unlimited Elements For Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-10081 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.0.11 2.0.11 2026-07-20
CVE-2026-57718 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.13 High 7.1 < 2.0.13 2.0.13 2026-07-09
CVE-2026-48837 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 2.0.9 2.0.9 2026-05-25
CVE-2026-5486 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 2.0.8 2.0.8 2026-05-13
CVE-2024-13362 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.5.141 1.5.141 2026-04-30
CVE-2026-4659 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.0.7 2.0.7 2026-04-16
CVE-2025-14274 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.0.2 2.0.2 2026-02-02
CVE-2025-13692 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.0.1 2.0.1 2025-11-26

CVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.

Source: CVE.org

CVE-2026-57718

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2026-48837

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

CVE-2026-5486

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the use of deprecated escaping functions combined with direct string concatenation in SQL query construction. The vulnerability is exacerbated because the normalizeAjaxInputData() function calls stripslashes() on all user input, removing the protection provided by WordPress's wp_magic_quotes() function. Subsequently, the filter_search parameter is escaped using the deprecated wpdb->_escape() function and then directly concatenated into a LIKE clause without using prepared statements. This makes it possible for authenticated attackers, with Contributor-level access and above (who can obtain a valid nonce through the Elementor editor), to inject arbitrary SQL commands and extract sensitive information from the database.

Source: CVE.org

CVE-2024-13362

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: CVE.org

CVE-2026-4659

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable debug output in widget settings. The URLtoRelative() function only performs a simple string replacement to remove the site's base URL without sanitizing path traversal sequences (../), and the cleanPath() function only normalizes directory separators without removing traversal components. This allows an attacker to provide a URL like http://site.com/../../../../etc/passwd which, after URLtoRelative() strips the domain, results in /../../../../etc/passwd being concatenated with the base path and ultimately resolved to /etc/passwd. This makes it possible for authenticated attackers with Author-level access and above to read arbitrary local files from the WordPress host, including sensitive files such as wp-config.

Source: CVE.org

CVE-2025-14274

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2025-13692

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. A form with a file upload field must be created with the premium version of the plugin in order to exploit the vulnerability. However, once the form exists, the vulnerability is exploitable even if the premium version is deactivated and/or uninstalled.

Source: CVE.org

+ 33 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13155 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.5.141 1.5.141 2025-02-19
CVE-2024-13153 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.136 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.5.136 1.5.136 2025-01-08
CVE-2024-10784 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.5.127 1.5.127 2024-12-11
CVE-2024-49271 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 Improper Neutralization of Script in Attributes of IMG Tags in a Web Page Critical 9.1 < 1.5.122 1.5.122 2024-10-14
CVE-2024-45454 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.5.122 1.5.122 2024-09-30
CVE-2024-6170 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.113 1.5.113 2024-07-08
CVE-2024-6169 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.113 1.5.113 2024-07-08
CVE-2024-6171 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 Use of Less Trusted Source Medium 5.3 < 1.5.113 1.5.113 2024-07-08
CVE-2024-6166 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.5.113 1.5.113 2024-07-08
CVE-2024-35674 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 Missing Authorization Medium 4.3 < 1.5.110 1.5.110 2024-06-05
CVE-2024-5329 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.5.110 1.5.110 2024-06-05
CVE-2024-3190 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.6 < 1.5.108 1.5.108 2024-05-29
CVE-2023-6743 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.91 Improper Control of Generation of Code ('Code Injection') High 8.8 < 1.5.91 1.5.91 2024-05-28
CVE-2024-4779 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.5.108 1.5.108 2024-05-22
CVE-2024-3055 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.5.105 1.5.105 2024-05-10
CVE-2024-2662 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') High 7.2 < 1.5.103 1.5.103 2024-05-09
CVE-2024-3547 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.5.103 1.5.103 2024-05-09
CVE-2024-0367 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.97 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.97 1.5.97 2024-03-29
CVE-2024-29792 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.94 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.5.94 1.5.94 2024-03-25
CVE-2023-33999 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.75 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.5.75 1.5.75 2023-07-18
CVE-2023-31080 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 Missing Authorization High 8.3 < 1.5.66 1.5.66 2023-06-20
CVE-2023-31231 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 1.5.66 1.5.66 2023-06-20
CVE-2023-3295 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.5.67 1.5.67 2023-06-16
CVE-2023-31090 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.61 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 1.5.61 1.5.61 2023-05-22
CVE-2023-33930 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 1.5.67 1.5.67 2023-05-22
CVE-2022-47170 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.49 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 1.5.49 1.5.49 2023-01-27
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 Missing Authorization Medium 6.3 < 1.5.3 1.5.3 2022-03-04
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 Unknown < 1.5.3 1.5.3 2022-02-28
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 Unknown < 1.5.3 1.5.3 2022-02-28
CVE-2025-1663 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.143 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.143 1.5.143 0000-00-00
CVE-2025-8603 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.149 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.5.149 1.5.149 0000-00-00
CVE-2026-2724 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.6 Unknown < 2.0.6 2.0.6 0000-00-00
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 Unknown < 1.5.3 1.5.3

CVE-2024-13155

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widget: Transparent Split Hero must be deleted and reinstalled manually.

Source: CVE.org

CVE-2024-13153

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widgets: Image Tooltip, Notification, Simple Popup, Video Play Button, and Card Carousel, must be deleted and reinstalled manually.

Source: CVE.org

CVE-2024-10784

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-49271

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.121 via the template engine. This is due to the plugin not properly restricting functions that can be called and passed to code execution functions. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

Source: Wordfence

CVE-2024-45454

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.121 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: Wordfence

CVE-2024-6170

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-6169

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-6171

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.

Source: CVE.org

CVE-2024-6166

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

CVE-2024-35674

<p>WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.109 is vulnerable to Broken Access Control</p><p>Software: Unlimited Elements For Elementor (Free Widgets, Addons, Templates)</p><p>Link: https://wordpress.org/plugins/unlimited-elements-for-elementor/#developers</p><p>Affected Version <= 1.5.109</p><p>Fixed in version 1.5.110 </p>

Source: Patchstack

CVE-2024-5329

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

CVE-2024-3190

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note that this vulnerability is different in that the issue stems from an external template. It appears that older version may also be patched due to this, however, we are choosing 1.5.108 as the patched version since that is the most recent version containing as known patch.

Source: CVE.org

CVE-2023-6743

<p>WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.89 is vulnerable to Remote Code Execution (RCE)</p><p>Software: Unlimited Elements For Elementor (Free Widgets, Addons, Templates)</p><p>Link: https://wordpress.org/plugins/unlimited-elements-for-elementor/#developers</p><p>Affected Version <= 1.5.89</p><p>Fixed in version 1.5.91 </p>

Source: Patchstack

CVE-2024-4779

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

CVE-2024-3055

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

CVE-2024-2662

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.

Source: CVE.org

CVE-2024-3547

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: CVE.org

CVE-2024-0367

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.97). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.97. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-29792

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.94). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.94. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2023-33999

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.75). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.75.

Source: Patchstack

CVE-2023-31080

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it possible for authenticated attackers, with contributor-level access and above, to perform a plethora of unauthorized actions such as updating/ deleting/modfying addons and modifying various settings.

Source: Wordfence

CVE-2023-31231

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.66). Rafie Muhammad (Patchstack) discovered and reported this Arbitrary File Upload vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 1.5.66.

Source: Patchstack

CVE-2023-3295

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.

Source: CVE.org

CVE-2023-31090

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files within zip files in the File Manager functionality in versions up to, and including, 1.5.60 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Source: Wordfence

CVE-2023-33930

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.67). Achref Ben Thameur discovered and reported this Bypass Vulnerability vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 1.5.67.

Source: Patchstack

CVE-2022-47170

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.49). Muhammad Daffa discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.49.

Source: Patchstack

Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

Source: Wordfence

Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).

Source: Patchstack

Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3

Sensitive Information Disclosure vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).

Source: Patchstack

CVE-2025-1663

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-8603

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2026-2724

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the trashed form entries.

Source: Wordfence

Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.