OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-85017

HIGH · CVSS 7.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Unlimited Elements For Elementor WordPress plugin prior to version 2.0.20 is vulnerable due to a lack of capability checks on an AJAX action, allowing authenticated attackers with subscriber-level access to inject arbitrary PHP objects through deserialized attacker-controlled data. This vulnerability can lead to unauthorized code execution, potentially compromising the integrity of the WordPress site. WordPress site administrators using affected versions should prioritize updating to version 2.0.20 or later to mitigate this risk.

CVE
CVE-2026-85017
Severity
HIGH
CVSS
7.5
EPSS
0.40%
WordPress

Original NVD Description

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.