rootpwn

medium · CVSS v3 5.4

CVE-2026-85016

Unlimited Elements for Elementor plugin before 2.0.21 fails to escape icon values, enabling XSS for users with Contributor role. The flaw al

Overview

Unlimited Elements for Elementor plugin before 2.0.21 fails to escape icon values, enabling XSS for users with Contributor role. The flaw allows malicious payloads to run when pages are rendered. It affects WordPress sites using the plugin.

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.

Impact

The vulnerability permits cross‑site scripting, compromising confidentiality by exfiltrating data, integrity by modifying page content, and potentially disrupting availability. Site administrators and users with Contributor access are directly impacted.

Remediation

Update the plugin to version 2.0.21 or later. If an update is not possible, remove the Contributor role or revoke unfiltered_html capability, and enforce a strict Content Security Policy. Additionally, sanitize icon inputs or disable the affected widget processor.

Risk context

The CVE has a medium severity rating with a CVSS v3 score of 5.4 and no EPSS data, indicating a moderate risk that should be addressed promptly but is not critical.

Affected products

  • Unlimited Elements for Elementor
  • WordPress
  • Elementor

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.4
CVSS v4
—
EPSS
—

XSS WordPress plugin Contributor unfiltered_html medium CVE-2026-85016

← All CVEs