The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.
References
Configurations
Configuration 1 (hide)
|
History
30 Jan 2025, 16:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Unlimited-elements
Unlimited-elements unlimited Elements For Elementor |
|
References | () https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_template_engine.class.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/58492dbb-b9e0-4477-b85d-ace06dba954c?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:unlimited-elements:unlimited_elements_for_elementor:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-78 |
21 Nov 2024, 09:10
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_template_engine.class.php - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/58492dbb-b9e0-4477-b85d-ace06dba954c?source=cve - |
14 May 2024, 15:20
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 15:20
Updated : 2025-01-30 16:12
NVD link : CVE-2024-2662
Mitre link : CVE-2024-2662
CVE.ORG link : CVE-2024-2662
JSON object : View
Products Affected
unlimited-elements
- unlimited_elements_for_elementor
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')