CVE-2026-95534: fallo de gravedad alta en Unlimited Elements For Elementor (Free…
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - PHP Object Injection vulnerability
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Unlimited Elements · Unlimited Elements For Elementor (Free Widgets, Addons, Templates)CVEs relacionadas — Unlimited Elements For Elementor (Free…
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-49271CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerabilityEPSS 1.1%CVE-2023-31090CRITICALWordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerabilityEPSS 0.8%CVE-2024-29792HIGHWordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.7%CVE-2023-31231CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2023-33930CRITICALWordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerabilityEPSS 0.5%CVE-2026-28146MEDIUMWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerabilityEPSS 0.4%