Unlimited Elements develops a plugin ecosystem for the Elementor page builder platform, offering a suite of widgets, addons, and template libraries that extend the builder's design and functionality capabilities. Despite a narrow product line, the vendor's disclosures reach a prominent position in the vulnerability landscape, reflecting the broad install base of Elementor-dependent sites and the supply-chain effect of plugin dependencies in WordPress-adjacent ecosystems. The vendor's vulnerability patterns have not yet coalesced around a dominant weakness class, suggesting exposure across varied implementation boundaries within its addon and widget offerings. Defenders should treat Elementor plugin dependencies as part of their site-hardening inventory, particularly where multiple addons layer on the same underlying builder; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unlimited Elements over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48837HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection.
This issue affec | May 25, 2026 | 8.5 | 31 | NO | NO |
CVE-2024-29792MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Tem | Mar 27, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-6166HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versio | Jul 9, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-5329HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions u | Jun 6, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-6743HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via | May 29, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-4779HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up | May 23, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-31090HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to | Apr 24, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-3295HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the fil | Jun 17, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-35674HIGH Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unl | Jun 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-3055HIGH The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, | May 14, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unlimited Elements.
Media articles that mention a CVE ID that affects a product developed by Unlimited Elements — matched by CVE ID, not by vendor name.