Sceawere

Vulnerability Detail

CVE-2026-103344UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Unlimited Elements

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-04T09:16:38.543Z",
  "pubdate": "2026-10-04T09:16:38.543Z",
  "executiveSummary": "The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper neutralization of user-supplied input during web page generation, allowing attackers to inject malicious scripts into the rendered HTML.\nThe vulnerability affects all versions from n/a through 2.0.20. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to unauthorized actions performed on behalf of the user, session hijacking via cookie theft, or the redirection of users to malicious third-party domains.\nBecause the attack is reflected, it typically requires the victim to click a specially crafted URL containing the malicious payload. The vulnerability poses a significant risk to administrative or authenticated users, as the injected script inherits the privileges of the victim's current session. No specific authentication is required to initiate the attack, as it relies on the browser's processing of untrusted input.",
  "technicalDetails": "The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw identified in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions 2.0.20 and below. The root cause of the vulnerability is the insufficient sanitization and validation of parameters processed by the plugin before they are reflected back to the user within the HTML response body.\nExploitation occurs when an attacker crafts a malicious URL containing a payload embedded within an input parameter that the plugin fails to properly neutralize. When a victim—typically an administrator or an authenticated user—clicks this crafted link, the web server processes the request and embeds the malicious script directly into the resulting document. The victim's browser, seeing the script as part of the page content, executes the arbitrary JavaScript code within the context of the site's origin.\nThe attack flow proceeds as follows: 1. The attacker identifies a vulnerable input parameter handled by the plugin. 2. The attacker constructs a URL containing a crafted JavaScript payload (e.g., <script>alert(document.cookie)</script>) targeting the vulnerable parameter. 3. The attacker social-engineers a target user into clicking the link. 4. Upon the user visiting the link, the server reflects the malicious payload into the rendered page. 5. The user's browser executes the script, allowing the attacker to perform actions such as stealing session cookies, capturing sensitive form data, modifying the DOM to display deceptive content, or facilitating credential harvesting via fake login forms.\nThis vulnerability is classified under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Because the reflected input is interpreted by the browser, the potential impact is high, particularly when the victim has elevated privileges. The vulnerability does not require the attacker to have pre-existing access to the WordPress backend; it relies entirely on the client-side execution triggered by the victim's interaction with the malicious payload. The scope of impact is confined to the specific site where the plugin is installed and active."
}
CVE-2026-103344: Reflected XSS in Unlimited Elements (HIGH Severity, CVSS: 7.1) | Sceawere