Sceawere

Vulnerability Detail

CVE-2026-103342UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Unlimited Elements

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-03T15:16:36.087Z",
  "pubdate": "2026-10-03T15:16:36.087Z",
  "executiveSummary": "The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), allows unauthenticated or authenticated attackers to inject malicious scripts into the web application, which are subsequently reflected back to the end-user's browser.\nThe affected versions range from n/a through 2.0.20.\nSuccessful exploitation allows an attacker to execute arbitrary JavaScript within the context of the victim's session.\nThe primary impact includes session hijacking, unauthorized actions performed on behalf of the user, theft of sensitive information, or the redirection of users to malicious websites.\nThis issue poses a significant risk to the integrity and confidentiality of the affected WordPress site's administrative or front-end user sessions.",
  "technicalDetails": "The vulnerability originates from the insufficient sanitization and validation of user-supplied input before rendering it back within the HTML response. In the context of Unlimited Elements For Elementor, the plugin fails to adequately neutralize parameters that are reflected in the generated web page content.\nAs a Reflected XSS vulnerability, the attack vector involves injecting a malicious payload (typically JavaScript code) into a crafted URL or request parameter. When a victim interacts with a link containing this payload, the web application processes the input and includes it directly in the HTML output without proper context-aware encoding.\nThe attack flow proceeds as follows: First, an attacker identifies a vulnerable input parameter handled by the Unlimited Elements plugin. Second, the attacker crafts a malicious URL containing a JavaScript payload encoded within that parameter. Third, the attacker lures an authenticated user or administrator to click the malicious link. Finally, the browser of the victim parses the response, identifies the injected script as legitimate code, and executes it within the victim's active session.\nBecause the payload executes in the context of the victim's browser, the attacker can bypass Same-Origin Policy (SOP) restrictions to access cookies (if not protected by HttpOnly flags), local storage, or perform sensitive administrative actions via the victim's authenticated state.\nThe vulnerable component resides within the core processing logic of the Unlimited Elements plugin that handles page generation. The vulnerability persists across all versions up to and including 2.0.20. Exploitation does not necessarily require administrative privileges if the reflected parameter is accessible on the front-end or through public-facing functionality; however, targeting administrators yields higher impact via unauthorized plugin configuration changes or account takeovers.\nThe lack of strict output encoding or context-dependent escaping at the points of reflection enables the injection of `<script>` tags, event handlers (e.g., onerror, onload), or other HTML elements capable of initiating script execution. Post-exploitation impact varies from minor UI defacement to complete compromise of the victim's session, enabling the attacker to perform any action the victim is authorized to perform on the WordPress site."
}
CVE-2026-103342: Reflected XSS in Unlimited Elements (HIGH Severity, CVSS: 7.1) | Sceawere