Sceawere
Vulnerability Detail
CVE-2026-92924UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unlimited Elements Arbitrary Shortcode Execution
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- Unlimited Elements for Elementor
- Attack Type
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-02T07:16:38.613Z",
"pubdate": "2026-10-02T07:16:38.613Z",
"executiveSummary": "The Unlimited Elements for Elementor WordPress plugin contains a critical security flaw involving the improper authorization of widget rendering requests. This vulnerability allows authenticated users to execute arbitrary WordPress shortcodes on the target site.\nThe vulnerability type is categorized as an improper access control issue, leading to potential unauthorized code execution. Affected versions include all instances prior to 2.0.21. In versions 2.0.18 through 2.0.20, the privilege requirement was restricted to the Contributor role; however, prior to 2.0.18, the vulnerability was exploitable by any user with a Subscriber role.\nThe primary risk implication involves the potential for privilege escalation, sensitive data exposure, or server-side manipulation, depending on the availability of existing shortcodes on the host environment. The attack requires authenticated access, which poses a significant threat in multi-user WordPress environments where user registration is enabled or lower-privileged accounts have been compromised.\nExploitation does not require elevated administrative privileges, making it a high-risk vector for malicious actors seeking to leverage legitimate plugin functionality to bypass security boundaries and trigger unintended server-side operations.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient authorization check within the Unlimited Elements for Elementor plugin's widget rendering mechanism. The plugin exposes an internal functionality intended to render widget output dynamically; however, the request handler fails to adequately validate the privileges of the requesting user against the requested operation.\nIn versions prior to 2.0.18, the implementation lacked any meaningful verification, allowing users with the Subscriber role to initiate requests to the vulnerable rendering endpoint. Subsequent updates (2.0.18 to 2.0.20) implemented a partial fix by restricting access to users with the Contributor role or higher. It was not until version 2.0.21 that the authorization logic was sufficiently hardened to address the flaw comprehensively.\nThe exploitation flow proceeds as follows: An authenticated attacker identifies the specific API endpoint or AJAX action used by the plugin to render widget shortcodes. By crafting a malicious request targeting this endpoint, the attacker passes parameters that cause the plugin to process an arbitrary shortcode string provided by the user. Because the plugin executes this shortcode via the WordPress `do_shortcode()` or similar rendering engine without enforcing appropriate capability checks, the server evaluates the shortcode within the context of the current request.\nThe impact of this execution is highly dependent on the shortcodes available within the specific WordPress installation. If a site utilizes shortcodes that perform database queries, file system operations, or interact with third-party integrated services, the attacker may be able to manipulate these features to exfiltrate data, perform unauthorized actions, or escalate their current privilege level by triggering shortcodes intended for higher-privileged users. The vulnerability effectively allows an attacker to bypass intended plugin restrictions by leveraging the plugin's own rendering engine as a proxy for arbitrary shortcode execution.\nGiven that this vulnerability operates through the plugin’s legitimate execution pathways, it is difficult to detect via traditional signature-based Web Application Firewalls (WAFs) unless they are configured to inspect and validate specific POST/GET parameter values related to the widget rendering process. The lack of granular capability checks means the plugin fails to follow the principle of least privilege, allowing any user who can reach the rendering function to trigger server-side code execution."
}