CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85016

MEDIUMCVSS 6.8NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-85016 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85016

MEDIUMCVSS 6.8NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when th

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]