OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103342

HIGH · CVSS 7.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Unlimited Elements for Elementor versions up to 2.0.20 are vulnerable to a reflected cross-site scripting (XSS) attack due to improper input neutralization during web page generation. This vulnerability could allow attackers to execute arbitrary scripts in the context of a user's browser, potentially leading to data theft or session hijacking. Website administrators and developers using this plugin should prioritize patching or upgrading to mitigate the risk associated with this high-severity vulnerability.

CVE
CVE-2026-103342
Severity
HIGH
CVSS
7.1
EPSS
0.15%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.