5,174 GPL Products · Updated DailyPRO Versions Available · Instant Download

Unlimited Elements for Elementor XSS Vulnerability (CVE-2026-103344): Update to 2.0.21+ Now (2026)

There’s a serious new Unlimited Elements for Elementor vulnerability that every WordPress site owner running this popular Elementor addon needs to know about. In October 2026, security researchers disclosed CVE-2026-103344: a HIGH-severity reflected cross-site scripting (XSS) flaw affecting every version of the plugin through 2.0.20. The attacker needs no account on your site — one crafted link, clicked by a logged-in user, is enough to execute malicious script inside that user’s browser session. The good news: the fix is simple and already available. Updating to version 2.0.21 or later closes the hole completely, and the patched 2.0.23 release is already downloadable from WPPlugg. In this security advisory we explain what happened, how to check whether you’re affected, what the flaw can do in the wrong hands, and how to patch it safely in minutes.

Quick answer: CVE-2026-103344 is a HIGH-severity reflected XSS vulnerability in Unlimited Elements for Elementor, affecting all versions through 2.0.20. If your site runs 2.0.20 or older, update to 2.0.21 or later immediately. The patched version 2.0.23 is already available on WPPlugg’s Unlimited Elements for Elementor page.

What Happened: CVE-2026-103344 at a Glance

Unlimited Elements for Elementor is a widely used free addon for Elementor that adds extra widgets, addons, and templates to the page builder. Because it renders widget output on the front end of countless sites, any input-handling flaw in it has an outsized blast radius — which is exactly what security researchers found.

Here are the verified facts about the flaw:

  • CVE identifier: CVE-2026-103344
  • Vulnerability type: Reflected cross-site scripting (XSS) — officially described as “improper neutralization of input during web page generation”
  • Severity: HIGH (CVSS 3.1, per multiple scoring sources)
  • Affected versions: Every version of Unlimited Elements for Elementor through 2.0.20
  • Fixed in: Version 2.0.21 and later
  • Disclosed: October 2026

Notably, this is not the first security fix this plugin has needed. The vendor has shipped several security patches across the 2.0.x line during 2026, which makes staying current on this particular plugin more important than most site owners realize. Version 2.0.21 contains the specific fix for CVE-2026-103344, and the current release — 2.0.23 — includes that fix plus everything that came after.

Am I Affected? Check Your Version in 30 Seconds

If Unlimited Elements for Elementor is installed on your site, you are affected whenever the installed version is 2.0.20 or older. Checking takes less than a minute:

  1. Log in to your WordPress dashboard.
  2. Go to Plugins → Installed Plugins.
  3. Find Unlimited Elements for Elementor in the list — the version number is shown right under the plugin name.
  4. Compare it against the table below.
Installed version Status Action
2.0.20 or older Vulnerable Update immediately
2.0.21 or 2.0.22 Patched No action needed for this CVE
2.0.23 (current) Patched You’re fully up to date

A quick shortcut: on the Plugins screen, WordPress shows an “update available” notice under any plugin with a pending update. If you see one under Unlimited Elements for Elementor, you’re behind — and given that this is a HIGH-severity flaw, that update should not wait until the weekend.

Reflected XSS, Explained in Plain English

Cross-site scripting sounds technical, but the core idea is simple. A reflected XSS flaw means the plugin takes something from a web request — part of a URL, a form field, a parameter — and echoes it back into the page without properly neutralizing it first. If that input contains a script, the script gets rendered as if it were a legitimate part of the page.

The word “reflected” matters. Unlike stored XSS, where the malicious payload is saved in your database and served to every visitor, a reflected payload only lives inside a single crafted link. Nothing on your site is permanently modified by the attack itself. But that single link is all it takes: the moment a logged-in user clicks it, the script executes in their browser, inside their authenticated session. Your site never looks compromised — which is precisely why this class of flaw is so effective.

The uncomfortable part: the attacker needs no login, no account, and no prior access to your site. The attack targets your users, not your server. A phishing-style email, a direct message, or a link dropped in a comment or forum can all serve as the delivery mechanism.

What an Attacker Could Do With This Flaw

A reflected XSS payload running inside an administrator’s session is far more dangerous than it sounds. Because the script executes with the victim’s privileges, it can potentially perform any action that user could perform: creating new admin accounts, installing plugins, modifying content, or exfiltrating data — all while appearing to come from a legitimate logged-in administrator.

Even against lower-privilege users, session-level script execution can be used to steal session cookies or authentication tokens, which can then be replayed to impersonate the victim. The practical takeaway is blunt: any site running 2.0.20 or older should treat the update as urgent, not routine. This is not a theoretical hardening recommendation — it is a disclosed, catalogued vulnerability with a public CVE identifier.

How to Update to the Patched Version Safely

Patching is straightforward, but a few minutes of care will save you from the rare bad surprise. Follow these steps:

  1. Take a backup first. A full site backup (files + database) before any plugin update is non-negotiable. If anything behaves unexpectedly after the update, you can roll back in minutes.
  2. Update the plugin. Go to Dashboard → Updates and update Unlimited Elements for Elementor to the latest version, or update it directly from Plugins → Installed Plugins. If you prefer manual updates, download the patched ZIP and use Plugins → Add New → Upload Plugin to install it over the existing copy — WordPress will replace the old files while keeping your settings.
  3. Confirm the version. After updating, revisit the Plugins screen and verify the version reads 2.0.21 or higher (2.0.23 is current).
  4. Spot-check your pages. Open a few pages built with Unlimited Elements widgets and confirm they render correctly. Point releases in the 2.0.x line are targeted fixes, so breakage is unlikely — but a two-minute visual check is cheap insurance.
  5. Turn on auto-updates if you haven’t. On the Plugins screen, enable automatic updates for this plugin. Security fixes only protect you if they’re actually installed, and auto-updates close the gap between disclosure and patching to zero.

Get the Patched Version 2.0.23

If your dashboard update isn’t cooperating — or you want a clean, verified copy of the patched release — you can grab it directly. WPPlugg already serves the fully patched version 2.0.23 of Unlimited Elements for Elementor as a GPL-licensed download, so you can update even if the built-in updater is misbehaving or your license key has lapsed.

Download the Patched Version Now

Get Unlimited Elements for Elementor 2.0.23 (includes the CVE-2026-103344 fix) as a GPL download — update your site and close this vulnerability today.

Download Unlimited Elements for Elementor 2.0.23

One Flaw, One Lesson: Harden the Rest of Your Stack

Patching CVE-2026-103344 is the urgent step, but it’s worth treating this advisory as a prompt for a broader checkup. Most compromised WordPress sites aren’t breached through exotic zero-days — they’re breached through known vulnerabilities in outdated plugins that had patches available for weeks or months.

Three habits that pay for themselves:

  • Update everything, promptly. Enable auto-updates for plugins and themes where you can, and review the Updates screen weekly. Attackers routinely scan for disclosed CVEs within days of publication.
  • Run a dedicated security plugin. A firewall and malware scanner adds a layer of defense between disclosed flaws and your site. Wordfence is the most widely deployed option and can block many exploit attempts even before you’ve patched.
  • Limit admin accounts. Reflected XSS targets users, so fewer privileged users means a smaller attack surface. Give collaborators the lowest role that lets them do their job, and remove accounts you no longer need.

Security in WordPress is rarely about any single plugin — it’s about the discipline of keeping the whole stack current. This week’s advisory is a reminder that the discipline matters.

Frequently Asked Questions

FAQs

How do I check which version of Unlimited Elements I’m running?
Go to Plugins → Installed Plugins in your WordPress dashboard and find “Unlimited Elements for Elementor” — the version number appears directly under the plugin name. If it reads 2.0.20 or lower, you’re vulnerable to CVE-2026-103344 and should update to 2.0.21 or later right away.
Am I affected if I only use the free version of the plugin?
Yes. The security advisory specifically names the free plugin — Unlimited Elements for Elementor (Free Widgets, Addons, Templates) — with all versions through 2.0.20 affected. The fix landed in version 2.0.21, so any installation on 2.0.20 or older needs the update regardless of which edition you use.
What is reflected XSS in simple terms?
Reflected cross-site scripting happens when a plugin echoes something from a web request (like part of a URL) back into a page without properly sanitizing it. An attacker crafts a special link containing a script; when a logged-in user clicks that link, the script runs inside their browser session with their privileges. The payload isn’t stored on your site — it only exists inside the crafted link — which is why it’s called “reflected.”
Will updating to 2.0.21 or later break my Elementor widgets?
Very unlikely. The 2.0.21 release is a targeted security fix, not a major rewrite, and point releases in the 2.0.x line are designed to be drop-in updates. Still, take a full backup before updating and spot-check a few pages that use Unlimited Elements widgets afterward — that’s standard practice for any plugin update.
What should I do after updating?
First, verify the new version number on the Plugins screen. Then do a quick security review: check Users → All Users for any administrator accounts you don’t recognize, and review recently modified content for anything unexpected. If anyone on your team clicked suspicious links while the site was vulnerable, have them change their passwords. Finally, enable auto-updates for the plugin so the next security fix installs itself.
Where can I download the patched version?
The patched release (currently 2.0.23, which includes the CVE-2026-103344 fix) is available as a GPL-licensed download from WPPlugg’s Unlimited Elements for Elementor page. You can upload the ZIP via Plugins → Add New → Upload Plugin to update an existing installation.

Leave a Comment