Junglewise Threat Intelligence

CVE-2026-66608: Unlimited Elements For Elementor server-side request forgery

CVE-2026-66608 · Severity: medium · CVSS 6.4 · Published 2026-09-17

Executive brief

Unlimited Elements For Elementor is a popular WordPress plugin that provides free widgets and templates for the Elementor page builder. A server-side request forgery (SSRF) vulnerability in versions up to 2.0.19 allows contributors to make the WordPress server connect to internal systems and leak sensitive data behind the firewall, potentially compromising internal network infrastructure and exposing confidential information.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw in Unlimited Elements For Elementor plugin versions 2.0.19 and earlier. It requires a user with the Contributor role or higher privileges to exploit. An attacker with contributor access can craft requests that cause the server to connect to arbitrary internal systems, allowing reconnaissance of the internal network and potential data exfiltration from services not directly accessible from the internet. The vendor has patched this issue in version 2.0.20 and later.

Affected products

  • Unlimited Elements Unlimited Elements For Elementor <= 2.0.19

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Version 2.0.20 released

References

Related threats