CVE-2026-92924: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Unlimited Elements for Elementor
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
AI Analysis
Technical Summary
The Unlimited Elements for Elementor plugin prior to version 2.0.21 does not properly verify that requests to render widget output originate from authorized users. This allows users with roles as low as subscriber (before 2.0.18) or Contributor (from 2.0.18 onward) to execute arbitrary WordPress shortcodes on the site. This is classified as CWE-74, improper neutralization of special elements in output used by a downstream component ('Injection').
Potential Impact
An attacker with subscriber or contributor privileges can execute arbitrary WordPress shortcodes, potentially leading to unauthorized content injection or manipulation within the site. The impact is limited to the privileges of the compromised user role and does not directly affect availability. The CVSS score is 5.4 (medium severity), indicating a moderate risk.
Mitigation Recommendations
Upgrade the Unlimited Elements for Elementor plugin to version 2.0.21 or later, where this vulnerability is fixed. Versions 2.0.18 and later have reduced the minimum role required to exploit this issue to Contributor, and 2.0.21 fully addresses the access control flaw. No other mitigations are indicated.
CVE-2026-92924: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Unlimited Elements for Elementor
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
CVSS v3.1
Score 5.4medium
Affected software
Unlimited Elements for Elementor
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Unlimited Elements for Elementor plugin prior to version 2.0.21 does not properly verify that requests to render widget output originate from authorized users. This allows users with roles as low as subscriber (before 2.0.18) or Contributor (from 2.0.18 onward) to execute arbitrary WordPress shortcodes on the site. This is classified as CWE-74, improper neutralization of special elements in output used by a downstream component ('Injection').
Potential Impact
An attacker with subscriber or contributor privileges can execute arbitrary WordPress shortcodes, potentially leading to unauthorized content injection or manipulation within the site. The impact is limited to the privileges of the compromised user role and does not directly affect availability. The CVSS score is 5.4 (medium severity), indicating a moderate risk.
Mitigation Recommendations
Upgrade the Unlimited Elements for Elementor plugin to version 2.0.21 or later, where this vulnerability is fixed. Versions 2.0.18 and later have reduced the minimum role required to exploit this issue to Contributor, and 2.0.21 fully addresses the access control flaw. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-17T11:19:22.002Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abf8f57a43b0b3b89ac0ade
Added to database: 10/02/2026, 11:02:47 UTC
Last enriched: 10/02/2026, 11:16:43 UTC
Last updated: 10/03/2026, 03:50:59 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.