CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-49271

CVSS 9.1v3.1pub. 2024-10-16upd. 2026-04-23

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.121.

🤖 AI Analysis
How it works

The vulnerability consists of deserialization of data from untrusted sources (CWE-82, CWE-94), which leads to command injection. An attacker with administrator-level privileges can upload crafted data that, after deserialization, is executed as system commands on the server. The flaw enables escaping the application context (Scope Changed), meaning it is possible to affect resources beyond the plugin itself.

Impact

An attacker can gain full access to sensitive data, modify or delete server content, and completely take control of the system on which the vulnerable application is running.

Mitigation & patch

Update the 'Unlimited Elements For Elementor' plugin to a version higher than 1.5.121. Detailed information about the available patch can be found in the vendor references and the Patchstack database.

Who is affected

Plugin 'Unlimited Elements For Elementor (Free Widgets, Addons, Templates)' for WordPress in versions from the beginning of releases up to and including 1.5.121.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Unlimited Elements For Elementor

    APP
    Unlimited-Elements
    < 1.5.122
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2023-33930CRITICAL9.1PL ✓same product

Nieograniczony upload plików w wtyczce Unlimited Elements For Elementor

CVE-2023-31090CRITICAL9.9PL ✓same product

Unrestricted File Upload umożliwiający Web Shell w pluginie Unlimited Elements For Elementor

CVE-2023-31231CRITICAL9.9PL ✓same product

Unrestricted File Upload w wtyczce Unlimited Elements For Elementor

CVE-2024-45454HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimite...

CVE-2023-31080HIGH8.3same product

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addo...