Unlimited Elements For Elementor <= 2.0.22 - Authenticated (Contributor+) Limited Arbitrary Function Call via Post List 'includeby_function_name' Setting

High 7.6 CWE-94Fixed in 2.0.23
ID
WPSEC-2026-0431
Plugin
Unlimited Elements for Elementor (unlimited-elements-for-elementor)
Affected
all versions before 2.0.23
Remediation
Update to 2.0.23 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Weakness
CWE-94
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-05
Attack surface
Unlimited Elements For Elementor on WPSec AttackSurface
Fix released
Published

Description

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to a limited arbitrary function call via the post list 'includeby_function_name' setting in all versions up to, and including, 2.0.22. The plugin only checked that the supplied function name began with 'get' before calling it with a user-controlled argument. This makes it possible for authenticated attackers with Contributor-level access and above who can edit Elementor content to call arbitrary PHP functions whose names start with 'get', which can lead to local PHP file inclusion or server-side requests.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0