CVE-2026-95534: high-severity vulnerability in Unlimited Elements For Elementor (Free…
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - PHP Object Injection vulnerability
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8
exploitation probability
—
observed exploitation
nono source reports it
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Unlimited Elements · Unlimited Elements For Elementor (Free Widgets, Addons, Templates)Related CVEs — Unlimited Elements For Elementor (Free…
In the same product, most dangerous first.
CVE-2024-49271CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerabilityEPSS 1.1%CVE-2023-31090CRITICALWordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerabilityEPSS 0.8%CVE-2024-29792HIGHWordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.7%CVE-2023-31231CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2023-33930CRITICALWordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerabilityEPSS 0.5%CVE-2026-28146MEDIUMWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerabilityEPSS 0.4%