AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-28146

MEDIUM · CVSS 6.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Unlimited Elements for Elementor versions up to 2.0.14 are vulnerable to an arbitrary file download issue, allowing attackers to potentially access sensitive files on the server. This could lead to data exposure and compromise the integrity of the affected websites. Website administrators using this plugin should prioritize patching or upgrading to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-28146
Severity
MEDIUM
CVSS
6.5
EPSS
0.33%

Original NVD Description

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.