Executive brief
Unlimited Elements for Elementor (Premium) is a popular WordPress plugin used to add advanced widgets and features to the Elementor page builder. A security flaw allows users with 'Contributor' level access to upload malicious files to the web server. If exploited, an attacker could gain full control over the website, potentially leading to data theft, site defacement, or the installation of backdoors.
Technical details
The Unlimited Elements for Elementor (Premium) plugin for WordPress is vulnerable to an Unrestricted Upload of File with Dangerous Type (CWE-434) in versions up to and including 2.0.6. This vulnerability allows an authenticated attacker with Contributor-level permissions or higher to upload arbitrary files, such as PHP scripts, to the server. Because the plugin fails to properly validate file extensions and content, these files can be executed remotely, leading to full site compromise (RCE). As of the advisory date, no official patch has been released, though third-party mitigation rules are available.
Affected products
- Studio Keren Aga LTD. Unlimited Elements for Elementor (Premium) <= 2.0.6
Timeline
- 2025-12-16: other: Vulnerability reported by researcher Phat RiO
- 2026-03-16: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: NVD publication date