CVE-2026-85016 PUBLISHED

Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter

Assigner: WPScan
Reserved: 02.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.

Product Status

Vendor Unknown
Product Unlimited Elements for Elementor
Versions Default: unaffected
  • affected from 0 to 2.0.21 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE