unlimited-elements records
27 published records for vendor unlimited-elements.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 37%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-862 Missing Authorization3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-348 Use of Less Trusted Source1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-3295No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File Uploadunlimited-elements · unlimited elements for elementor · CWE-434 | High8.8 | — | 1.3% | Jun 16, 2023 |
35Monitor | CVE-2023-6743No exploit | Unlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template importunlimited-elements · unlimited elements for elementor · CWE-1336 | High8.8 | — | 1.3% | May 29, 2024 |
35Monitor | CVE-2024-3055No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Contributor+) SQL Injectionunlimited-elements · unlimited elements for elementor · CWE-89 | High8.8 | — | 0.8% | May 14, 2024 |
35Monitor | CVE-2023-31090No exploit | WordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-434 | High8.8 | — | 0.8% | Apr 24, 2024 |
35Monitor | CVE-2024-1710No exploit | Addon Library <= 1.3.76 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Uploadunlimited-elements · addon library · CWE-862 | High8.8 | — | 0.7% | Feb 26, 2024 |
35Monitor | CVE-2024-5329No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameterunlimited-elements · unlimited elements for elementor · CWE-89 | High8.8 | — | 0.5% | Jun 6, 2024 |
35Monitor | CVE-2024-6166No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injectionunlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\) · CWE-89 | High8.8 | — | 0.5% | Jul 9, 2024 |
35Monitor | CVE-2024-4779No exploit | Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[post_ids][0]unlimited-elements · unlimited elements for elementor · CWE-89 | High8.8 | — | 0.5% | May 23, 2024 |
35Monitor | CVE-2023-31080No exploit | WordPress Unlimited Elements For Elementor plugin <= 1.5.65 - Multiple Broken Access Control vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-862 | High8.8 | — | 0.4% | Jun 9, 2024 |
35Monitor | CVE-2024-35674No exploit | WordPress Unlimited Elements For Elementor plugin <= 1.5.109 - Broken Access Control vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-862 | High8.8 | — | 0.4% | Jun 5, 2024 |
29Monitor | CVE-2024-2662No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injectionunlimited-elements · unlimited elements for elementor · CWE-78 | High7.2 | — | 1.7% | May 14, 2024 |
28Monitor | CVE-2024-49271No exploit | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-82 | High7.2 | — | 1.1% | Oct 16, 2024 |
28Monitor | CVE-2023-33930No exploit | WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-434 | High7.2 | — | 0.5% | Jun 4, 2024 |
26Monitor | CVE-2023-31231No exploit | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File Uploadunlimited-elements · unlimited elements for elementor · CWE-434 | Medium6.5 | — | 0.7% | Dec 20, 2023 |
24Monitor | CVE-2024-29792Proof of concept | WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-79 | Medium6.1 | — | 0.7% | Mar 27, 2024 |
24Monitor | CVE-2024-3547No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scriptingunlimited-elements · unlimited elements for elementor · CWE-79 | Medium6.1 | — | 0.4% | May 14, 2024 |
24Monitor | CVE-2024-45454No exploit | WordPress Unlimited Elements for Elementor plugin <= 1.5.121 - Reflected Cross Site Scripting (XSS) vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-79 | Medium6.1 | — | 0.3% | Oct 6, 2024 |
21Monitor | CVE-2024-6169No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'username'unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\) · CWE-79 | Medium5.4 | — | 0.5% | Jul 9, 2024 |
21Monitor | CVE-2024-6170No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'email'unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\) · CWE-79 | Medium5.4 | — | 0.5% | Jul 9, 2024 |
21Monitor | CVE-2024-10784No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scriptingunlimited-elements · unlimited elements for elementor · CWE-79 | Medium5.4 | — | 0.4% | Dec 12, 2024 |
21Monitor | CVE-2024-13155No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hunlimited-elements · unlimited elements for elementor · CWE-79 | Medium5.4 | — | 0.4% | Feb 20, 2025 |
21Monitor | CVE-2024-0367No exploit | Unlimited Elements For Elementor <= 1.5.96 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Linkunlimited-elements · unlimited elements for elementor · CWE-79 | Medium5.4 | — | 0.3% | Mar 30, 2024 |
21Monitor | CVE-2024-13153No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgetsunlimited-elements · unlimited elements for elementor · CWE-79 | Medium5.4 | — | 0.3% | Jan 9, 2025 |
21Monitor | CVE-2024-6171No exploit | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypassunlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\) · CWE-348 | Medium5.3 | — | 0.2% | Jul 9, 2024 |
21Monitor | CVE-2025-1663No exploit | Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scriptingunlimited-elements · unlimited elements for elementor · CWE-79 | Medium5.4 | — | 0.2% | Apr 3, 2025 |
- CVE-2023-329535Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · unlimited elements for elementorJun 16, 2023
- CVE-2023-674335Monitor
Unlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template import
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · unlimited elements for elementorMay 29, 2024
- CVE-2024-305535Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Contributor+) SQL Injection
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · unlimited elements for elementorMay 14, 2024
- CVE-2023-3109035Monitor
WordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerability
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · unlimited elements for elementorApr 24, 2024
- CVE-2024-171035Monitor
Addon Library <= 1.3.76 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · addon libraryFeb 26, 2024
- CVE-2024-532935Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter
HighCVSS 8.8No exploitEPSS 1%unlimited-elements · unlimited elements for elementorJun 6, 2024
- CVE-2024-616635Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injection
HighCVSS 8.8No exploitEPSS 0%unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\)Jul 9, 2024
- CVE-2024-477935Monitor
Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[post_ids][0]
HighCVSS 8.8No exploitEPSS 0%unlimited-elements · unlimited elements for elementorMay 23, 2024
- CVE-2023-3108035Monitor
WordPress Unlimited Elements For Elementor plugin <= 1.5.65 - Multiple Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%unlimited-elements · unlimited elements for elementorJun 9, 2024
- CVE-2024-3567435Monitor
WordPress Unlimited Elements For Elementor plugin <= 1.5.109 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%unlimited-elements · unlimited elements for elementorJun 5, 2024
- CVE-2024-266229Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injection
HighCVSS 7.2No exploitEPSS 2%unlimited-elements · unlimited elements for elementorMay 14, 2024
- CVE-2024-4927128Monitor
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability
HighCVSS 7.2No exploitEPSS 1%unlimited-elements · unlimited elements for elementorOct 16, 2024
- CVE-2023-3393028Monitor
WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerability
HighCVSS 7.2No exploitEPSS 1%unlimited-elements · unlimited elements for elementorJun 4, 2024
- CVE-2023-3123126Monitor
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File Upload
MediumCVSS 6.5No exploitEPSS 1%unlimited-elements · unlimited elements for elementorDec 20, 2023
- CVE-2024-2979224Monitor
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1Proof of conceptEPSS 1%unlimited-elements · unlimited elements for elementorMar 27, 2024
- CVE-2024-354724Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%unlimited-elements · unlimited elements for elementorMay 14, 2024
- CVE-2024-4545424Monitor
WordPress Unlimited Elements for Elementor plugin <= 1.5.121 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%unlimited-elements · unlimited elements for elementorOct 6, 2024
- CVE-2024-616921Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'username'
MediumCVSS 5.4No exploitEPSS 1%unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\)Jul 9, 2024
- CVE-2024-617021Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'email'
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\)Jul 9, 2024
- CVE-2024-1078421Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementorDec 12, 2024
- CVE-2024-1315521Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.140 - Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split H
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementorFeb 20, 2025
- CVE-2024-036721Monitor
Unlimited Elements For Elementor <= 1.5.96 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementorMar 30, 2024
- CVE-2024-1315321Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.135 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementorJan 9, 2025
- CVE-2024-617121Monitor
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass
MediumCVSS 5.3No exploitEPSS 0%unlimited-elements · unlimited elements for elementor \(free widgets\, addons\, templates\)Jul 9, 2024
- CVE-2025-166321Monitor
Unlimited Elements For Elementor <= 1.5.142 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%unlimited-elements · unlimited elements for elementorApr 3, 2025