CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-85015: Unlimited Elements for Elementor 0 to before 2.0.21

CVE-2026-85015. CVSS 3.1 base score 6.6 (MEDIUM, Source advisory). EPSS 0.00219 (percentile 0.11259), scored 03-Oct-2026.

Affected technology

Unlimited Elements for Elementor · 0 to before 2.0.21
Vendor not specified by the source

Description’s affected range: before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Authenticated users with access can its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution. Source advisory’s CVSS 3.1 assessment (base score 6.6/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-22
CCR priority
26.5 /100 (P4)
CVSS 3.1
6.6 /10 · CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00421 · percentile 0.34492 · 2026-10-10
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-85015.html