rootpwn

medium · CVSS v3 6.3 · EPSS 0.00156

CVE-2026-92923

The Unlimited Elements for Elementor WordPress plugin contains a blind SQL injection flaw that can be exploited by users with low privileges

Overview

The Unlimited Elements for Elementor WordPress plugin contains a blind SQL injection flaw that can be exploited by users with low privileges. The vulnerability exists in versions prior to 2.0.21 and allows attackers to read arbitrary database data. Upgrading the plugin mitigates the risk.

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.

Impact

Confidentiality: attackers can read sensitive data from the WordPress database. Integrity: no direct modification but data exposure. Availability: not directly affected. Defenders: site owners, admins, and users with Contributor role or higher.

Remediation

Upgrade Unlimited Elements for Elementor to version 2.0.21 or later. If an upgrade is not possible, restrict Contributor and higher roles to trusted users or disable the plugin. Monitor database queries for suspicious activity.

Risk context

The CVE has a medium severity score of 6.3 and a very low EPSS of 0.00156, indicating a low probability of exploitation in the wild, but defenders should still apply the fix promptly.

Affected products

  • WordPress
  • Unlimited Elements for Elementor
  • Elementor plugin
  • WP plugin

Scores

Severity
medium
CVSS v2
4.9
CVSS v3
6.3
CVSS v4
—
EPSS
0.00156

sql-injection wordpress plugin medium subscriber contributor data-exposure

← All CVEs