{"api_version":"1","generated_at":"2026-10-03T21:56:35+00:00","cve":"CVE-2026-85015","urls":{"html":"https://cve.report/CVE-2026-85015","api":"https://cve.report/api/cve/CVE-2026-85015.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-85015","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-85015"},"summary":{"title":"Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal","description":"The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-10-03 06:16:43","updated_at":"2026-10-03 16:16:39"},"problem_types":["CWE-22","CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://wpscan.com/vulnerability/aefcaecf-024d-4ec7-9b67-69d21addea7b/","name":"https://wpscan.com/vulnerability/aefcaecf-024d-4ec7-9b67-69d21addea7b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-85015","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85015","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Unlimited Elements for Elementor","version":"affected 2.0.21 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Yaswanth Reddy Sunkara","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-85015","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-10-03T15:05:48.603836Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-03T15:12:22.336Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Unlimited Elements for Elementor","vendor":"Unknown","versions":[{"lessThan":"2.0.21","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Yaswanth Reddy Sunkara"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution."}],"problemTypes":[{"descriptions":[{"description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-03T06:00:25.673Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/aefcaecf-024d-4ec7-9b67-69d21addea7b/"}],"source":{"discovery":"EXTERNAL"},"title":"Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-85015","datePublished":"2026-10-03T06:00:25.673Z","dateReserved":"2026-09-02T19:18:43.920Z","dateUpdated":"2026-10-03T15:12:22.336Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-03 06:16:43","lastModifiedDate":"2026-10-03 16:16:39","problem_types":["CWE-22","CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-03T15:05:48.603836Z","id":"CVE-2026-85015","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"85015","Ordinal":"1","Title":"Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitr","CVE":"CVE-2026-85015","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"85015","Ordinal":"1","NoteData":"The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress plugin before 2.0.21 setting is enabled) to write arbitrary files, including executable PHP, outside the intended upload directory on servers where the PHP zip extension is unavailable, leading to Remote Code Execution.","Type":"Description","Title":"Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitr"}]}}}