Sceawere

Vulnerability Detail

CVE-2026-85015UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unlimited Elements Arbitrary File Write

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.6
Creation Date
13h ago
Vendor
Unknown
Product
Unlimited Elements for Elementor
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.6",
  "pubDate": "2026-10-03T06:16:43.247Z",
  "pubdate": "2026-10-03T06:16:43.247Z",
  "executiveSummary": "Unlimited Elements for Elementor WordPress plugin versions prior to 2.0.21 contain a critical vulnerability involving improper sanitization of file paths within uploaded archives. This flaw facilitates an Arbitrary File Write vulnerability, which can be leveraged to achieve Remote Code Execution (RCE).\nThe vulnerability occurs during the extraction process of uploaded zip archives managed by the plugin's asset-management feature. Because the plugin fails to validate or sanitize file paths contained within these archives, an attacker can utilize directory traversal sequences (e.g., ../) to escape the intended upload directory.\nThis vulnerability is particularly severe on server environments where the PHP zip extension is unavailable, as the fallback mechanism implemented by the plugin fails to perform necessary security checks. Exploitation requires authenticated access with the ability to use the asset-management feature; by default, this is restricted to Administrators, though it may extend to Editors depending on specific plugin configurations.\nSuccessful exploitation allows an attacker to write arbitrary files to the server, including malicious PHP scripts. Once a malicious script is placed in an accessible web directory, the attacker can execute arbitrary code, leading to complete site compromise, data exfiltration, and lateral movement within the hosting environment.",
  "technicalDetails": "The root cause of this vulnerability is a path traversal flaw within the file extraction logic of the Unlimited Elements for Elementor plugin. Specifically, when the plugin processes uploaded archives, it fails to perform adequate validation of the filenames or paths encoded within the zip entry headers.\nIn environments where the native PHP zip extension is absent, the plugin employs an alternative extraction mechanism. This implementation lacks the robust directory traversal protections expected in secure archive handling libraries. Consequently, a maliciously crafted archive containing entries with path components such as '../' allows the extraction process to write files to arbitrary locations on the filesystem, relative to the base extraction directory.\nThe attack flow begins with an authenticated user (typically an Administrator or an Editor, depending on plugin settings) accessing the plugin's asset-management functionality. The attacker uploads a crafted archive containing at least one malicious file (e.g., a PHP shell) with a filename path that includes directory traversal sequences. For instance, a file entry named '../../../../var/www/html/shell.php' would attempt to escape the intended storage directory and write directly into the web root.\nBecause the server-side extraction logic does not sanitize these paths, the system interprets the traversal sequences and attempts to write the file content to the target destination. If the web server process has sufficient write permissions to the target directory, the file is successfully placed on the server.\nPost-exploitation, the attacker can navigate to the URL corresponding to the uploaded malicious file. Since the file is a PHP script, the web server executes it upon the request, granting the attacker Remote Code Execution. This provides an interface to execute system commands, manipulate the WordPress database, modify core files, or establish persistence via backdoors. The impact is critical as it bypasses standard file upload security controls and provides a direct path to total system control within the context of the web server's service account privileges."
}
CVE-2026-85015: Unlimited Elements Arbitrary File Write (MEDIUM Severity, CVSS: 6.6) | Sceawere