CVE-2026-85015
Received Received - Intake

Path Traversal in Unlimited Elements for Elementor

Vulnerability report for CVE-2026-85015, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
unlimited_elements unlimited_elements_for_elementor to 2.0.21 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Unlimited Elements For Elementor' versions before 2.0.21. It allows authenticated users with access to the plugin's asset-management feature to perform path traversal attacks. The plugin fails to sanitize file paths when extracting uploaded archives, enabling users to write arbitrary files outside the intended upload directory. This can lead to remote code execution even without the PHP zip extension.

Detection Guidance

Check if the Unlimited Elements for Elementor plugin is installed and verify its version. If the version is below 2.0.21, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

An attacker with access to the asset-management feature could upload a malicious archive containing a PHP file. If extracted, this file could be placed outside the intended directory, allowing the attacker to execute arbitrary code on the server. This could lead to full control over the WordPress site and potentially the underlying server.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and security. Organizations may face legal penalties, reputational damage, and loss of trust due to compromised sensitive data.

Mitigation Strategies

Update the Unlimited Elements for Elementor plugin to version 2.0.21 or later immediately. If updating is not possible, restrict access to the asset-management feature for non-administrator users to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85015. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart