Vulnerabilities / Unlimited Elements For Elementor / WPSEC-2026-0431
Unlimited Elements For Elementor <= 2.0.22 - Authenticated (Contributor+) Limited Arbitrary Function Call via Post List 'includeby_function_name' Setting
High 7.6
CWE-94Fixed in 2.0.23
- ID
- WPSEC-2026-0431
- Plugin
- Unlimited Elements for Elementor (unlimited-elements-for-elementor)
- Affected
- all versions before 2.0.23
- Remediation
- Update to 2.0.23 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- Weakness
- CWE-94
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-05
- Attack surface
- Unlimited Elements For Elementor on WPSec AttackSurface
- Fix released
- Published
Description
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to a limited arbitrary function call via the post list 'includeby_function_name' setting in all versions up to, and including, 2.0.22. The plugin only checked that the supplied function name began with 'get' before calling it with a user-controlled argument. This makes it possible for authenticated attackers with Contributor-level access and above who can edit Elementor content to call arbitrary PHP functions whose names start with 'get', which can lead to local PHP file inclusion or server-side requests.
References
- https://wpsec.com/vuln/WPSEC-2026-0431/
- https://plugins.svn.wordpress.org/unlimited-elements-for-elementor/tags/2.0.23/
- https://wordpress.org/plugins/unlimited-elements-for-elementor/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS