CVE-2026-10081
Received Received - Intake

Stored XSS in Unlimited Elements For Elementor Plugin

Vulnerability report for CVE-2026-10081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
unlimited_elements unlimited_elements_for_elementor to 2.0.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated stored cross-site scripting (XSS) vulnerability in the Unlimited Elements for Elementor WordPress plugin before version 2.0.11. The plugin fails to sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget. Attackers can exploit this by submitting a malicious review on a business's Google listing, which then delivers the XSS payload to any visitor viewing a WordPress page displaying those reviews.

Detection Guidance

Check if the 'Unlimited Elements for Elementor' plugin is installed and its version is below 2.0.11. Inspect WordPress pages using the Google Reviews widget for unusual scripts or payloads in review content. Review server logs for suspicious activity related to the widget.

Impact Analysis

If you use an affected version of the plugin, attackers can inject malicious scripts into your WordPress site via Google reviews. These scripts can execute for any visitor, including administrators, potentially stealing session cookies, redirecting users to malicious sites, or performing actions on their behalf. This could lead to unauthorized access, data theft, or further compromise of your website.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing user data to attackers through XSS attacks. GDPR requires protecting user data and ensuring confidentiality, while HIPAA mandates safeguarding protected health information. A successful XSS attack could result in unauthorized access to such data, violating these regulations and potentially leading to legal penalties or reputational damage.

Mitigation Strategies

Update the 'Unlimited Elements for Elementor' plugin to version 2.0.11 or later immediately. Remove or disable the Google Reviews widget if not essential. Monitor for unauthorized changes or suspicious activity on affected pages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart