{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-28147","assignerOrgId":"21595511-bba5-4825-b968-b78d1f9984a3","state":"PUBLISHED","assignerShortName":"Patchstack","dateReserved":"2026-02-25T12:14:24.000Z","datePublished":"2026-08-03T07:09:38.328Z","dateUpdated":"2026-08-03T15:37:10.864Z"},"containers":{"cna":{"providerMetadata":{"orgId":"21595511-bba5-4825-b968-b78d1f9984a3","shortName":"Patchstack","dateUpdated":"2026-08-03T07:09:38.328Z"},"title":"WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-862","description":"CWE-862 Missing Authorization","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-180","descriptions":[{"lang":"en","value":"CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"}]}],"affected":[{"vendor":"Unlimited Elements","product":"Unlimited Elements For Elementor (Free Widgets, Addons, Templates)","collectionURL":"https://wordpress.org/plugins","packageName":"unlimited-elements-for-elementor","versions":[{"status":"affected","version":"n/a","lessThanOrEqual":"2.0.15","changes":[{"at":"2.0.16","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.","supportingMedia":[{"type":"text/html","base64":false,"value":"Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.<p>This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.</p>"}]}],"tags":["x_open-source"],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-15-broken-access-control-vulnerability?_s_id=cve","tags":["vdb-entry"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}}],"solutions":[{"lang":"en","value":"Update the WordPress Unlimited Elements For Elementor plugin to the latest available version (at least 2.0.16).","supportingMedia":[{"type":"text/html","base64":false,"value":"Update the WordPress Unlimited Elements For Elementor plugin to the latest available version (at least 2.0.16)."}]}],"credits":[{"lang":"en","value":"TurboNexic | Patchstack Bug Bounty Program","user":"00000000-0000-4000-9000-000000000000","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-03T14:02:07.889592Z","id":"CVE-2026-28147","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-03T15:37:10.864Z"}}]}}