# Unlimited Elements For Elementor <= 2.0.22 - Authenticated (Contributor+) Limited Arbitrary Function Call via Post List 'includeby_function_name' Setting

- **ID:** WPSEC-2026-0431
- **Plugin:** Unlimited Elements for Elementor (`unlimited-elements-for-elementor`), https://wordpress.org/plugins/unlimited-elements-for-elementor/
- **Affected versions:** all versions before 2.0.23
- **Fixed in:** 2.0.23 (Update to 2.0.23 or later.)
- **Severity:** High 7.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L)
- **Weakness:** CWE-94
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-05)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/unlimited-elements-for-elementor
- **Fix released:** 2026-10-04
- **Published:** 2026-10-05
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0431/

## Description

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to a limited arbitrary function call via the post list 'includeby_function_name' setting in all versions up to, and including, 2.0.22. The plugin only checked that the supplied function name began with 'get' before calling it with a user-controlled argument. This makes it possible for authenticated attackers with Contributor-level access and above who can edit Elementor content to call arbitrary PHP functions whose names start with 'get', which can lead to local PHP file inclusion or server-side requests.

## References

- https://wpsec.com/vuln/WPSEC-2026-0431/
- https://plugins.svn.wordpress.org/unlimited-elements-for-elementor/tags/2.0.23/
- https://wordpress.org/plugins/unlimited-elements-for-elementor/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0431/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
