CVE-2026-103344

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-04: 110-04
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 4 Oct 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Unpatched single sign-on server — unauthenticated class loading, cross-realm session theft, OAuth2 SSRF (Open Identity Platform OpenAM CVE-2026-105115, CVE-2026-105114, CVE-2026-105116, CVE-2026-105117, CVE-2026-105118, CVE-2026-105120, CVE-2026-105121, CVE-2026-105122) 📦 Outdated WordPress plugins — SQL injection, privilege escalation, cross-site scripting (Unlimited Elements CVE-2026-103355, CVE-2026-103342, CVE-2026-103344; Ultimate Member CVE-2026-96451; TranslatePress CVE-2026-103062; Kadence Blocks CVE-2026-103354; WP Statistics CVE-2026-97276) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #SSO #CSO #REDTEAM

    0000050
    6 followersView on X

Explore more