WordPress Plugin Vulnerabilities

Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter

Description

The plugin does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-09-30 (about 2 days ago)
Added
2026-09-30 (about 1 day ago)
Last Updated
2026-09-30 (about 1 day ago)

Other