Impact
The Unlimited Elements For Elementor WordPress plugin contains an input validation flaw where the addontype parameter is concatenated directly into an SQL WHERE clause without proper escaping. When an attacker supplies the parameter as an array, the first element is treated as the SQL comparison operator and inserted verbatim, allowing the execution of arbitrary SQL statements. This flaw corresponds to the injection weakness identified as CWE‑89 and enables unauthenticated attackers to read or tamper with database contents, including user credentials and configuration data.
Affected Systems
All installations of the plugin with version 2.0.16 or earlier are affected. Any WordPress site that has not upgraded past this release will be vulnerable regardless of the hosting environment or the presence of other plugins.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. Disclosure does not require authentication, which increases exploitability; attackers can reach the vulnerable endpoint via a crafted HTTP request. Although the EPSS score is not published and the flaw is not yet listed in the CISA KEV catalog, the combination of high impact, vector simplicity, and wide distribution means that exploitation is both feasible and potentially damaging.
OpenCVE Enrichment