CVE-2026-4659Disclosure

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable debug output in widget settings. The URLtoRelative() function only performs a simple string replacement to remove the site's base URL without sanitizing path traversal sequences (../), and the cleanPath() function only normalizes directory separators without removing traversal components. This allows an attacker to provide a URL like http://site.com/../../../../etc/passwd which, after URLtoRelative() strips the domain, results in /../../../../etc/passwd being concatenated with the base path and ultimately resolved to /etc/passwd. This makes it possible for authenticated attackers with Author-level access and above to read arbitrary local files from the WordPress host, including sensitive files such as wp-config.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-17); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-17: 4Mentions · 2026-05-02: 2PoC Mentioned / Linked · 2026-04-17: 1Exploit Tool / Code · 2026-04-17: 1Patch / Workaround · 2026-05-02: 2Technical Details · 2026-04-17: 4Technical Details · 2026-05-02: 204-1705-02
Signal classification3 categories
Disclosure
466.7%
PoC
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-174
Disclosure3PoC1
2026-05-022
Disclosure1Patch1
Full discourse6 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    Reflected XSS in GiveWP <3.19.0 via unsanitized give-clear-update param. Unauth attacker phishes admins for JS exec, session hijack. CVSS 7.1. Patch now. #CVE-2024-11921 #XSS #WordPress #DevSecOps #DevOps #Developers infosec: https://www.valtersit.com/cve/2026/04/cve-2026-4659/

    Post summary

    The tweet details a reflected XSS flaw in GiveWP (<3.19.0) that could allow unauthorized JavaScript execution and session hijacking, provides a CVSS score of 7.1, and confirms a patch is now available.

    0000067
    889 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-4659: Unlimited Elements plugin &lt;=2.0.6 allows any Author to read arbitrary files via path traversal in URLtoRelative(). No patch exists. Fix your own damn code or pull the plugin. #InfoSec #WordPress #devsecops #developers #hackers info: https://www.valtersit.com/cve/2026/04/cve-2026-4659/

    Post summary

    The tweet announces CVE‑2026‑4659 affecting Unlimited Elements plugin <=2.0.6, describing a path traversal that allows arbitrary file reads, notes the lack of a patch, and advises developers to fix their own code or remove the plugin.

    0000057
    889 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4659-unlimited-elements-for-elementor-version-2-0-6-high-vulnerability-proof-of-concept CVE-2026-4659 #WordPress plugin #vulnerability unlimited-elements-for-elementor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsec…

    Post summary

    The post promotes a proof‑of‑concept for CVE‑2026‑4659, detailing a high‑severity flaw in Unlimited Elements for Elementor v2.0.6, but it does not mention active exploitation, patches, or debunking information.

    0000050
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4659 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including,… https://www.cve.org/CVERecord?id=CVE-2026-4659

    Post summary

    The post announces that Unlimited Elements for Elementor has an arbitrary file read flaw (CVE-2026-4659) via a URL parameter, but does not provide PoC, exploit, or patch details.

    0000058
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4659 Arbitrary File Read in Unlimited Elements for Elementor Plugin Up to 2.0.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4659

    Post summary

    CVE-2026-4659 is an arbitrary file read vulnerability affecting Elementor Plugin up to version 2.0.6, with no PoC, exploit, or patch details mentioned in the text.

    0000029
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-4659 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CS… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-4659 #WordPress #CyberSecurity #InfoSec

    Post summary

    A high‑severity CVE-2026-4659 is disclosed for Unlimited Elements in Elementor, exposing an arbitrary file read flaw with a CVSS score of 7.5, and it includes a link to a detailed analysis.

    000000
    145 followersView on X

Explore more