Executive brief
Unlimited Elements For Elementor is a popular WordPress plugin that provides free widgets and templates for the Elementor page builder. A server-side request forgery (SSRF) vulnerability in versions up to 2.0.19 allows contributors to make the WordPress server connect to internal systems and leak sensitive data behind the firewall, potentially compromising internal network infrastructure and exposing confidential information.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw in Unlimited Elements For Elementor plugin versions 2.0.19 and earlier. It requires a user with the Contributor role or higher privileges to exploit. An attacker with contributor access can craft requests that cause the server to connect to arbitrary internal systems, allowing reconnaissance of the internal network and potential data exfiltration from services not directly accessible from the internet. The vendor has patched this issue in version 2.0.20 and later.
Affected products
- Unlimited Elements Unlimited Elements For Elementor <= 2.0.19
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Version 2.0.20 released