Sceawere
Vulnerability Detail
CVE-2026-103344UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Unlimited Elements
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 4h ago
- Vendor
- Unlimited Elements
- Product
- Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-04T09:16:38.543Z",
"pubdate": "2026-10-04T09:16:38.543Z",
"executiveSummary": "The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper neutralization of user-supplied input during web page generation, allowing attackers to inject malicious scripts into the rendered HTML.\nThe vulnerability affects all versions from n/a through 2.0.20. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to unauthorized actions performed on behalf of the user, session hijacking via cookie theft, or the redirection of users to malicious third-party domains.\nBecause the attack is reflected, it typically requires the victim to click a specially crafted URL containing the malicious payload. The vulnerability poses a significant risk to administrative or authenticated users, as the injected script inherits the privileges of the victim's current session. No specific authentication is required to initiate the attack, as it relies on the browser's processing of untrusted input.",
"technicalDetails": "The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw identified in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions 2.0.20 and below. The root cause of the vulnerability is the insufficient sanitization and validation of parameters processed by the plugin before they are reflected back to the user within the HTML response body.\nExploitation occurs when an attacker crafts a malicious URL containing a payload embedded within an input parameter that the plugin fails to properly neutralize. When a victim—typically an administrator or an authenticated user—clicks this crafted link, the web server processes the request and embeds the malicious script directly into the resulting document. The victim's browser, seeing the script as part of the page content, executes the arbitrary JavaScript code within the context of the site's origin.\nThe attack flow proceeds as follows: 1. The attacker identifies a vulnerable input parameter handled by the plugin. 2. The attacker constructs a URL containing a crafted JavaScript payload (e.g., <script>alert(document.cookie)</script>) targeting the vulnerable parameter. 3. The attacker social-engineers a target user into clicking the link. 4. Upon the user visiting the link, the server reflects the malicious payload into the rendered page. 5. The user's browser executes the script, allowing the attacker to perform actions such as stealing session cookies, capturing sensitive form data, modifying the DOM to display deceptive content, or facilitating credential harvesting via fake login forms.\nThis vulnerability is classified under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Because the reflected input is interpreted by the browser, the potential impact is high, particularly when the victim has elevated privileges. The vulnerability does not require the attacker to have pre-existing access to the WordPress backend; it relies entirely on the client-side execution triggered by the victim's interaction with the malicious payload. The scope of impact is confined to the specific site where the plugin is installed and active."
}