medium · CVSS v3 5.4
CVE-2026-85016
Unlimited Elements for Elementor plugin before 2.0.21 fails to escape icon values, enabling XSS for users with Contributor role. The flaw al
Overview
Unlimited Elements for Elementor plugin before 2.0.21 fails to escape icon values, enabling XSS for users with Contributor role. The flaw allows malicious payloads to run when pages are rendered. It affects WordPress sites using the plugin.
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
Impact
The vulnerability permits cross‑site scripting, compromising confidentiality by exfiltrating data, integrity by modifying page content, and potentially disrupting availability. Site administrators and users with Contributor access are directly impacted.
Remediation
Update the plugin to version 2.0.21 or later. If an update is not possible, remove the Contributor role or revoke unfiltered_html capability, and enforce a strict Content Security Policy. Additionally, sanitize icon inputs or disable the affected widget processor.
Risk context
The CVE has a medium severity rating with a CVSS v3 score of 5.4 and no EPSS data, indicating a moderate risk that should be addressed promptly but is not critical.
Affected products
- Unlimited Elements for Elementor
- WordPress
- Elementor
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.4
- CVSS v4
- —
- EPSS
- —