PT-2025-48269 · WordPress · Unlimited Elements For Elementor

0Xvenus

+2

·

Published

2025-11-27

·

Updated

2025-11-27

·

CVE-2025-13692

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Unlimited Elements For Elementor plugin for WordPress versions prior to 2.1
Description The Unlimited Elements For Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting through SVG File uploads. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary web scripts into pages when a user accesses the SVG file. Exploitation requires a form with a file upload field created using the premium version of the plugin, but the issue remains exploitable even after deactivation or uninstallation of the premium version.
Recommendations Update to version 2.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13692

Affected Products

Unlimited Elements For Elementor