medium · CVSS v3 6.3 · EPSS 0.00156
CVE-2026-92923
The Unlimited Elements for Elementor WordPress plugin contains a blind SQL injection flaw that can be exploited by users with low privileges
Overview
The Unlimited Elements for Elementor WordPress plugin contains a blind SQL injection flaw that can be exploited by users with low privileges. The vulnerability exists in versions prior to 2.0.21 and allows attackers to read arbitrary database data. Upgrading the plugin mitigates the risk.
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Impact
Confidentiality: attackers can read sensitive data from the WordPress database. Integrity: no direct modification but data exposure. Availability: not directly affected. Defenders: site owners, admins, and users with Contributor role or higher.
Remediation
Upgrade Unlimited Elements for Elementor to version 2.0.21 or later. If an upgrade is not possible, restrict Contributor and higher roles to trusted users or disable the plugin. Monitor database queries for suspicious activity.
Risk context
The CVE has a medium severity score of 6.3 and a very low EPSS of 0.00156, indicating a low probability of exploitation in the wild, but defenders should still apply the fix promptly.
Affected products
- WordPress
- Unlimited Elements for Elementor
- Elementor plugin
- WP plugin
Scores
- Severity
- medium
- CVSS v2
- 4.9
- CVSS v3
- 6.3
- CVSS v4
- —
- EPSS
- 0.00156