CVE-2026-84820
largeUnauthenticated Cross-Site Scripting in Unlimited Elements for Elementor WordPress Plugin
CVE-2026-84820 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the Unlimited Elements For Elementor (Free Widgets, Addons, Templates) WordPress plugin, affecting all releases up to and including version 2.0.17. Because no privileges are required (PR:N) but user interaction is needed (UI:R), an unauthenticated attacker can get malicious script content rendered in a victim's browser — typically via a crafted link or injected content that the plugin outputs without adequate sanitization — and the attack only fires when a victim, often a logged-in user or site admin, views that content. Successful exploitation executes attacker-controlled JavaScript in the context of the affected site, which can lead to session/cookie theft, unwanted actions performed with the victim's privileges (such as modifying settings or creating admin users), or redirects to attacker-controlled pages; the CVSS scope change (S:C) reflects that the script escapes the plugin's context into the surrounding site. Any WordPress site running the free Unlimited Elements for Elementor plugin at version 2.0.17 or older is affected, which — given the plugin's large install base — plausibly means on the order of 100,000+ sites. There are currently no signs of active exploitation: the flaw is not in CISA's KEV, EPSS assigns a ~0.1% probability of exploitation within 30 days, and no public proof-of-concept is known.
What to do: Update Unlimited Elements For Elementor to the latest available release above 2.0.17 as soon as practical. Until patched, exercise caution with unsolicited links to pages of affected sites rendered by the plugin, and after updating review site pages and user accounts for unexpected injected scripts or unauthorized admin users. No public PoC or in-the-wild exploitation is known at this time, so routine patching rather than emergency response is appropriate.
| Unlimited Elements For Elementor (Free Widgets, Addons, Templates) — WordPress plugin | <= 2.0.17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.