VendorsUnlimited Elementsunlimited_elements_for_elementorany version
Vulnerabilities

Unlimited Elements for Elementor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2023-31090
WordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerability
Published 2024-04-24 · Modified
9.9EPSS 0.008
CVE-2023-31231
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File Upload
Published 2023-12-20 · Modified
9.9EPSS 0.007
CVE-2024-49271
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability
Published 2024-10-16 · Modified
9.1EPSS 0.011
CVE-2023-33930
WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerability
Published 2024-06-04 · Analyzed
9.1EPSS 0.005
CVE-2023-3295
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File Upload
Published 2023-06-17 · Modified
8.8EPSS 0.013
CVE-2023-6743
Unlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template import
Published 2024-05-29 · Modified
8.8EPSS 0.013
CVE-2024-3055
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Contributor+) SQL Injection
Published 2024-05-10 · Modified
8.8EPSS 0.008
CVE-2024-5329
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter
Published 2024-06-06 · Modified
8.8EPSS 0.005
CVE-2024-4779
Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[post_ids][0]
Published 2024-05-23 · Modified
8.8EPSS 0.005
CVE-2023-31080
WordPress Unlimited Elements For Elementor plugin <= 1.5.65 - Multiple Broken Access Control vulnerability
Published 2024-06-09 · Modified
8.8EPSS 0.004
CVE-2024-35674
WordPress Unlimited Elements For Elementor plugin <= 1.5.109 - Broken Access Control vulnerability
Published 2024-06-05 · Modified
8.8EPSS 0.004
CVE-2024-2662
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injection
Published 2024-05-10 · Modified
7.2EPSS 0.017
CVE-2024-29792
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.007
CVE-2024-45454
WordPress Unlimited Elements for Elementor plugin <= 1.5.121 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-10-06 · Modified
7.1EPSS 0.003
CVE-2024-10784
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-12-12 · Analyzed
6.4EPSS 0.004
CVE-2024-13155
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget
Published 2025-02-20 · Analyzed
6.4EPSS 0.004
CVE-2024-0367
Unlimited Elements For Elementor <= 1.5.96 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link
Published 2024-03-30 · Modified
6.4EPSS 0.003
CVE-2024-13153
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Published 2025-01-09 · Modified
6.4EPSS 0.003
CVE-2025-1663
Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-04-03 · Analyzed
6.4EPSS 0.002
CVE-2024-3547
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting
Published 2024-05-10 · Modified
6.1EPSS 0.004
CVE-2022-47170
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.48 is vulnerable to Cross Site Scripting (XSS)
Published 2023-03-28 · Modified
5.9EPSS 0.004
CVE-2024-3190
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.107 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Field
Published 2024-05-30 · Modified
5.4EPSS 0.003