What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.121.
Explanation of Vulnerability in Simple Terms
02Summary
Unlimited Elements For Elementor contains a vulnerability that allows high-privilege users to modify site content and functionality across the entire site. An attacker with administrator or editor access can exploit this flaw to alter pages, inject malicious code, or disable features. The vulnerability affects all versions up to 1.5.121. Site owners should update immediately to a version newer than 1.5.121.
What an attacker can do
03Attacker Capabilities
Modify site content, inject code, or alter functionality across the entire site.
Potential impact on your site
04Site Impact
A compromised admin or editor account can alter any page or inject malicious content sitewide.
Conditions required to exploit
05Prerequisites
Attacker must have high-level site access (administrator or editor role).
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 28, 2026
Record updated