Junglewise Threat Intelligence

CVE-2026-85017: Unlimited Elements For Elementor PHP object injection in AJAX handler

CVE-2026-85017 · Severity: high · CVSS 7.5 · Published 2026-09-20

Technologies: Unlimited Elements for Elementor. Vendors: Unlimited Elements.

Executive brief

Unlimited Elements For Elementor is a WordPress plugin that extends the Elementor page builder with additional UI components. The plugin fails to validate user permissions on a specific AJAX action and deserializes untrusted data, allowing authenticated users with basic subscriber access to inject malicious PHP objects that could lead to arbitrary code execution on the website.

Technical details

The vulnerability is a PHP object injection (CWE-502) in an AJAX action handler that deserializes attacker-controlled data without proper capability checks. Authenticated attackers with subscriber-level privileges can craft malicious serialized PHP objects to achieve code execution. A partial fix in versions 2.0.18–2.0.19 elevated the required privilege to editor-level, and the issue was fully patched in version 2.0.20.

Affected products

  • Unlimited Elements Unlimited Elements For Elementor before 2.0.20

Timeline

  • 2026-09-18: disclosed
  • 2026-09-20: patched: Fully resolved in 2.0.20; partial fix in 2.0.18–2.0.19

References

Related threats