CRITICAL 9.3 CVE-2026-103355 Published 4 Oct 2026

Unlimited Elements for Elementor Plugin Blind SQL Injection Vulnerability

Worried this affects your website?

A vulnerability has been disclosed in Unlimited Elements For Elementor (Free Widgets, Addons, Templates), also known by the plugin slug unlimited-elements-for-elementor. The plugin fails to properly neutralize special elements used in an SQL command, allowing Blind SQL Injection.

This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates) from n/a through 2.0.20.

Reference: CVE-2026-103355 on NVD

← Back to Security News