CRITICAL
9.3 CVE-2026-103355 Published 4 Oct 2026
Unlimited Elements for Elementor Plugin Blind SQL Injection Vulnerability
Worried this affects your website?
A vulnerability has been disclosed in Unlimited Elements For Elementor (Free Widgets, Addons, Templates), also known by the plugin slug unlimited-elements-for-elementor. The plugin fails to properly neutralize special elements used in an SQL command, allowing Blind SQL Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates) from n/a through 2.0.20.
Reference: CVE-2026-103355 on NVD
← Back to Security News