CVE-2026-85015 PUBLISHED

Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal

Assigner: WPScan
Reserved: 02.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution.

Product Status

Vendor Unknown
Product Unlimited Elements for Elementor
Versions Default: unaffected
  • affected from 0 to 2.0.21 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE