CVE-2026-85016 | Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress Widget Parameter Processor icon cross site scripting
A vulnerability, which was classified as problematic, has been found in Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress. Impacted is an unknown function of the component Widget Parameter Processor. This manipulation of the argument icon causes cross site scripting.
This vulnerability is registered as CVE-2026-85016. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More