Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.121.
The vulnerability consists of deserialization of data from untrusted sources (CWE-82, CWE-94), which leads to command injection. An attacker with administrator-level privileges can upload crafted data that, after deserialization, is executed as system commands on the server. The flaw enables escaping the application context (Scope Changed), meaning it is possible to affect resources beyond the plugin itself.
An attacker can gain full access to sensitive data, modify or delete server content, and completely take control of the system on which the vulnerable application is running.
Update the 'Unlimited Elements For Elementor' plugin to a version higher than 1.5.121. Detailed information about the available patch can be found in the vendor references and the Patchstack database.
Plugin 'Unlimited Elements For Elementor (Free Widgets, Addons, Templates)' for WordPress in versions from the beginning of releases up to and including 1.5.121.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HUnlimited Elements For Elementor
APPUnlimited-Elements< 1.5.122
Related vulnerabilities
Nieograniczony upload plików w wtyczce Unlimited Elements For Elementor
Unrestricted File Upload umożliwiający Web Shell w pluginie Unlimited Elements For Elementor
Unrestricted File Upload w wtyczce Unlimited Elements For Elementor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimite...
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addo...