What the vulnerability does
01Description
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.109.
Explanation of Vulnerability in Simple Terms
02Summary
Unlimited Elements For Elementor fails to properly check user permissions before allowing access to certain administrative functions. A logged-in user with low privileges can view sensitive information they should not have access to. The vulnerability affects versions up to 1.5.109. Update to a version newer than 1.5.109 to resolve this issue.
What an attacker can do
03Attacker Capabilities
View sensitive information restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Unauthorized users can access restricted data, potentially exposing site configuration or other users' information.
Conditions required to exploit
05Prerequisites
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
June 5, 2024
CVE published
May 11, 2026
Record updated