Executive brief
Unlimited Elements for Elementor is a popular WordPress plugin that adds advanced widgets and design capabilities to the Elementor page builder. A broken access control vulnerability allows unauthenticated attackers to access pages and perform actions they should not be authorized to perform, potentially exposing sensitive data or enabling unauthorized modifications to website content.
Technical details
This vulnerability is a broken access control (CWE-284) issue in the Unlimited Elements for Elementor WordPress plugin through version 2.0.17. The plugin fails to properly validate user permissions when accessing certain pages or functionality, allowing unauthenticated attackers to bypass authorization checks via network access. No authentication is required, and no user interaction is needed to exploit the vulnerability. An attacker can access restricted pages or data that should only be available to authorized users. The vulnerability was patched in version 2.0.18.
Affected products
- Unlimited Elements Unlimited Elements for Elementor through 2.0.17
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fixed in version 2.0.18