Junglewise Threat Intelligence

CVE-2026-57718: Unlimited Elements For Elementor Reflected XSS

CVE-2026-57718 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Unlimited Elements for Elementor. Vendors: Unlimited Elements.

Executive brief

Unlimited Elements for Elementor is a popular WordPress plugin used to add custom widgets and templates to websites. A security flaw in this plugin allows attackers to inject malicious scripts into the site, which are then executed in the browsers of other users. If successful, an attacker could redirect visitors to malicious websites, display unauthorized advertisements, or potentially hijack administrative sessions if a site owner clicks a specially crafted link.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Unlimited Elements For Elementor plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows unauthenticated remote attackers to inject arbitrary web scripts or HTML by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation requires user interaction and can lead to session hijacking or unauthorized actions in the context of the victim's browser. The issue affects all versions up to and including 2.0.12 and is resolved in version 2.0.13.

Affected products

  • Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) through 2.0.12

Timeline

  • 2026-06-30: disclosed: Reported by Taylsec
  • 2026-07-09: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE-2026-57718
  • 2026-07-09: patched: Version 2.0.13 released to address the vulnerability

References

Related threats