Executive brief
Unlimited Elements For Elementor is a WordPress plugin that extends the Elementor page builder with additional UI components. The plugin fails to validate user permissions on a specific AJAX action and deserializes untrusted data, allowing authenticated users with basic subscriber access to inject malicious PHP objects that could lead to arbitrary code execution on the website.
Technical details
The vulnerability is a PHP object injection (CWE-502) in an AJAX action handler that deserializes attacker-controlled data without proper capability checks. Authenticated attackers with subscriber-level privileges can craft malicious serialized PHP objects to achieve code execution. A partial fix in versions 2.0.18–2.0.19 elevated the required privilege to editor-level, and the issue was fully patched in version 2.0.20.
Affected products
- Unlimited Elements Unlimited Elements For Elementor before 2.0.20
Timeline
- 2026-09-18: disclosed
- 2026-09-20: patched: Fully resolved in 2.0.20; partial fix in 2.0.18–2.0.19