Junglewise Threat Intelligence

CVE-2026-10081: Unlimited Elements For Elementor Stored XSS in Google Reviews widget

CVE-2026-10081 · Severity: info · CVSS 8.8 · Published 2026-07-20

Executive brief

A vulnerability in the Unlimited Elements For Elementor WordPress plugin allows attackers to inject malicious scripts into a website by posting a review on a business's Google listing. When the plugin fetches and displays these reviews, the malicious code can execute in the browsers of site visitors and administrators. This could lead to unauthorized actions being performed on the website, such as administrative account takeover or the theft of sensitive session information.

Technical details

The Unlimited Elements For Elementor plugin for WordPress fails to sanitize or escape Google review content retrieved via the Serp API before rendering it in the Google Reviews widget. An unauthenticated attacker can exploit this by submitting a malicious review containing JavaScript to a business's Google listing. When the plugin fetches this review and displays it on a WordPress page using the affected widget, the script executes in the context of any user viewing the page. This is a Stored XSS vulnerability (CWE-79) that can lead to session hijacking or administrative actions if an admin views the page. The issue is fixed in version 2.0.11.

Affected products

  • Unlimited Elements Unlimited Elements For Elementor < 2.0.11

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory: WPScan advisory published
  • 2026-07-20: advisory: NVD published CVE-2026-10081
  • patched: Fixed in version 2.0.11

References

Related threats