The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
References
Configurations
Configuration 1 (hide)
|
History
10 Apr 2025, 14:02
Type | Values Removed | Values Added |
---|---|---|
First Time |
Unlimited-elements
Unlimited-elements unlimited Elements For Elementor |
|
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3258648%40unlimited-elements-for-elementor&new=3258648%40unlimited-elements-for-elementor&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/d07c43e0-783a-499b-b172-d058583d0749?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:unlimited-elements:unlimited_elements_for_elementor:*:*:*:*:*:wordpress:*:* |
07 Apr 2025, 14:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Apr 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-03 08:15
Updated : 2025-04-10 14:02
NVD link : CVE-2025-1663
Mitre link : CVE-2025-1663
CVE.ORG link : CVE-2025-1663
JSON object : View
Products Affected
unlimited-elements
- unlimited_elements_for_elementor
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')