CVE-2026-2724Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the trashed form entries.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-10: 3Technical Details · 2026-03-10: 303-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2724 - Elementor Stored Cross-Site Scripting Vulnerability Intel Report: https://ift.tt/jT7z8BY

    Post summary

    Cyberdebidivash Sentinel Apex has announced the discovery of CVE-2026-2724, a stored XSS vulnerability in Elementor, with details accessible via the provided Intel report link.

    0000031
    345 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2724 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2… https://www.cve.org/CVERecord?id=CVE-2026-2724 ----- Traducción: CVE-2026-2724 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑2724, describing a stored XSS flaw in the Unlimited Elements Elementor plugin for WordPress in all versions up to 2.x, without mentioning PoC, exploit, active use, or patch information.

    0000033
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2724 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2… https://www.cve.org/CVERecord?id=CVE-2026-2724

    Post summary

    The text announces CVE‑2026‑2724, describing it as a stored XSS vulnerability in the Unlimited Elements for Elementor plugin. It provides some technical details but no PoC, exploit, or mitigation.

    00000239
    56.7K followersView on X

Explore more