# CVE-2024-49271

## Summary

- **CVE ID:** CVE-2024-49271
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1336, CWE-82
- **Published:** Oct 16, 2024
- **Last Modified:** Apr 23, 2026

## Description

: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows : Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.

## Affected Products

- Unlimited Elements — Unlimited Elements For Elementor (Free Widgets, Addons, Templates) (n/a)
- Unlimited Elements — Unlimited Elements For Elementor (Free Widgets, Addons, Templates) (0)

## References

- [CNA](https://patchstack.com/database/vulnerability/unlimited-elements-for-elementor/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-1-5-121-remote-code-execution-rce-vulnerability?_s_id=cve)
- [CNA](https://patchstack.com/database/Wordpress/Plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-1-5-121-remote-code-execution-rce-vulnerability?_s_id=cve)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.14%
- **EPSS Percentile:** 64.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._