Sceawere

Vulnerability Detail

CVE-2026-105064UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unsafe Reflection in Unlimited Elements

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Attack Type
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.22.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:11.140Z",
  "pubdate": "2026-10-05T09:17:11.140Z",
  "executiveSummary": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates) is susceptible to a critical vulnerability classified as Use of Externally-Controlled Input to Select Classes or Code, commonly referred to as Unsafe Reflection (CWE-470).\nThis vulnerability exists in versions up to and including 2.0.22 and allows for Parameter Injection.\nThe flaw stems from insufficient validation of user-supplied input used to instantiate objects or execute code paths within the plugin's framework.\nSuccessful exploitation permits an unauthenticated or low-privileged attacker to manipulate internal application logic, potentially leading to unauthorized data access, remote code execution (RCE), or arbitrary file manipulation, depending on the specific application state.\nThe risk implication is severe, as it grants attackers the ability to influence the execution flow of the WordPress environment.\nThere are no explicit authentication requirements mentioned for triggering the initial injection vector, suggesting a potentially broad attack surface if the affected entry point is exposed to the public internet.\nImmediate remediation is required to prevent compromise of the WordPress host environment.",
  "technicalDetails": "The vulnerability is rooted in the improper handling of user-controlled parameters that dictate class instantiation or method invocation through reflection mechanisms. In the context of Unlimited Elements For Elementor versions 2.0.22 and prior, the application fails to adequately sanitize or whitelist inputs before they are utilized to dynamically select and execute code paths.\nWhen an application utilizes reflection to dynamically load classes based on external input without strict validation, it creates an 'Unsafe Reflection' scenario. An attacker can supply a malicious or unexpected class name, or manipulate parameters passed to these classes, effectively altering the application's intended operational logic.\nThe attack flow begins when an attacker sends a crafted HTTP request containing malicious parameter values directed at the vulnerable component of the plugin. These parameters are subsequently processed by the plugin's reflection logic. Because the input is not constrained to a predefined, safe list of classes, the reflection mechanism proceeds to instantiate or invoke the requested, unauthorized class or method.\nThis behavior facilitates Parameter Injection, where an attacker can provide unexpected arguments to internal functions. By controlling which objects are instantiated, an attacker may be able to bypass existing security controls, trigger secondary vulnerabilities, or force the application to perform actions with the privileges of the WordPress process. For instance, if an attacker successfully forces the instantiation of a class designed for administrative tasks or file system operations, they could achieve Remote Code Execution (RCE) or escalate privileges within the WordPress environment.\nThe impact of this vulnerability is high, as it grants the attacker significant control over the application's runtime environment. Post-exploitation, an attacker could potentially gain persistence, exfiltrate sensitive database information, or modify plugin settings to further weaken the security posture of the WordPress installation. The vulnerability affects all versions up to 2.0.22, and the lack of robust input validation at the reflection boundary is the primary technical failure point.\nThe attack is network-exposed, requiring no complex interaction from an administrator. The primary requirement is the reachability of the plugin's dynamic code-loading interface."
}
CVE-2026-105064: Unsafe Reflection in Unlimited Elements (MEDIUM Severity, CVSS: 6.5) | Sceawere