What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65.
Explanation of Vulnerability in Simple Terms
02Summary
Unlimited Elements For Elementor allows authenticated users with low privileges to upload files without restriction. An attacker can upload malicious files—including PHP scripts—to execute arbitrary code on the site. The vulnerability affects all versions up to 1.5.65. Site owners should update immediately to a version newer than 1.5.65.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files, including PHP code, to take control of the site.
Potential impact on your site
04Site Impact
Complete site compromise: attacker can read data, modify content, create admin accounts, or delete the site.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
December 20, 2023
CVE published
April 28, 2026
Record updated