Impact
The plugin fails to properly escape special characters in user‑supplied input used in an SQL statement, allowing an attacker to perform a blind SQL injection that can read, modify, or delete data in the site's database. This flaw can lead to confidentiality loss, integrity violations, and potentially disrupt application functionality.
Affected Systems
Unlimited Elements’s Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin is affected. All installations running a version from the initial release up to and including version 2.0.20 are vulnerable. The plugin is distributed through WordPress.
Risk and Exploitability
The CVSS score of 9.3 signals a high severity risk. No EPSS information is available, but the absence of an entry in CISA’s KEV catalog suggests no public exploit is known. The vulnerability can be triggered via the plugin’s public interfaces, potentially by unauthenticated or authenticated users depending on how the plugin processes input, so the attack vector is likely remote. Given the high score and the ability to extract sensitive data, urgent patching or mitigation measures are recommended.
OpenCVE Enrichment