Sceawere

Vulnerability Detail

CVE-2026-85016UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Unlimited Elements

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
17h ago
Vendor
Unknown
Product
Unlimited Elements for Elementor
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-02T06:16:41.903Z",
  "pubdate": "2026-10-02T06:16:41.903Z",
  "executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability exists within the Unlimited Elements for Elementor WordPress plugin versions prior to 2.0.21.\nThe vulnerability stems from improper neutralization of user-supplied input within the shared widget-parameter processor.\nThis flaw allows authenticated users with the 'Contributor' role, who do not possess the 'unfiltered_html' capability, to inject and store malicious JavaScript payloads.\nWhen a victim, such as an administrator, views the rendered page containing the compromised widget, the payload executes within the context of the user's browser session.\nThe impact includes potential account takeover, session hijacking, unauthorized actions performed on behalf of the victim, or the modification of the website's visual content.\nGiven that the vulnerability can be exploited by low-privileged users and results in client-side script execution, it poses a significant risk to the integrity and security of the WordPress installation.",
  "technicalDetails": "The root cause of this vulnerability is an inadequate input validation and output encoding implementation within the plugin's shared widget-parameter processor. Specifically, the plugin fails to properly escape an icon value before it is concatenated into an HTML attribute within the generated markup for the widget.\nIn the context of the WordPress plugin's architecture, the widget-parameter processor is responsible for handling user-defined settings for various Elementor widgets. When a user with 'Contributor' access creates or modifies an Elementor page or template, they interact with these parameters. The vulnerability occurs because the 'icon' parameter does not undergo sufficient sanitization before being inserted into the Document Object Model (DOM).\nAn attacker with the 'Contributor' role can exploit this by intercepting the request or utilizing the Elementor interface to inject a crafted payload into the icon parameter. For example, by inserting an attribute-breaking sequence such as '\" onmouseover=\"alert(1)' or similar JavaScript-executing event handlers, the attacker can break out of the intended HTML attribute context.\nThe attack flow proceeds as follows: First, the attacker saves the malicious payload via the widget settings. The server then stores this unsanitized input in the WordPress database, typically within the post content or meta fields. Subsequently, when the page is visited or rendered in the Elementor preview, the vulnerable component retrieves the malicious data and outputs it directly into the HTML without sanitization. The browser interprets the injected attribute as valid HTML, triggering the execution of the JavaScript payload under the security domain of the site.\nBecause the payload is stored persistently in the database, the vulnerability is classified as 'Stored XSS'. This persists until the malicious code is manually removed or the plugin is updated to version 2.0.21 or higher. The exploitation requires authenticated access to the Elementor interface, which is standard for a Contributor-level user. The lack of 'unfiltered_html' capability is bypassed because the input processing occurs through the plugin's specific widget settings, which may inadvertently permit the injection due to the flawed processing logic."
}
CVE-2026-85016: Stored XSS in Unlimited Elements (MEDIUM Severity, CVSS: 6.8) | Sceawere