1 vulnerability across 1 product scored HIGH or above on October 04, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 13.4 (HIGH โ†’ CRITICAL). Originally in 2026-09-30 bulletin.
  • [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) โ€” F1: exploitable โ†’ functional, AAS: 9.2 โ†’ 11.2 (HIGH โ†’ HIGH). Originally in 2026-09-28 bulletin.

๐ŸŸ  [HIGH] unlimited_elements/unlimited_elements_for_elementor_(free_widgets,_addons,_templates)

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:unlimited_elements:unlimited_elements_for_elementor:*:*:*:*:*:*:*:* (< 2.0.21)

Unlimited Elements for Elementor (Free Widgets, Addons, Templates) versions up to and including 2.0.20 are affected by a critical blind SQL injection vulnerability (CVE-2026-103355, CVSS 9.3). This flaw allows attackers to manipulate database queries, potentially extracting sensitive data or compromising the entire WordPress site. The vulnerability is considered exploitable, making prompt action essential.

WordPress administrators using this popular Elementor add-on plugin should update immediately to a patched version. If an update is not yet available, consider temporarily deactivating the plugin and monitoring the Patchstack advisory for remediation guidance. Given the severity and the large install base of Elementor ecosystem plugins, security teams should prioritize scanning their WordPress environments for this plugin and ensure no instances remain on the vulnerable version.

Vendor Advisory