Input validation vulnerability in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 1.5.60

The Unlimited Elements For Elementor plugin (which includes Free Widgets, Addons, and Templates) for WordPress is vulnerable to a type of security threat known as arbitrary file uploads. This type of vulnerability is due to the lack of validating the file type of files within zip files in the File Manager functionality for versions 1.5.60 and below. This means that an attacker who has a Contributor-level permission or higher can upload arbitrary files to the server of the affected website, which could potentially lead to remote code execution.

Detected in:

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) fixed vulnerable versions: >= * <= 1.5.60

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.