Description
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated SQL injection capable of extracting sensitive database information
Action: Patch Now
AI Analysis

Impact

The Unlimited Elements For Elementor WordPress plugin contains an input validation flaw where the addontype parameter is concatenated directly into an SQL WHERE clause without proper escaping. When an attacker supplies the parameter as an array, the first element is treated as the SQL comparison operator and inserted verbatim, allowing the execution of arbitrary SQL statements. This flaw corresponds to the injection weakness identified as CWE‑89 and enables unauthenticated attackers to read or tamper with database contents, including user credentials and configuration data.

Affected Systems

All installations of the plugin with version 2.0.16 or earlier are affected. Any WordPress site that has not upgraded past this release will be vulnerable regardless of the hosting environment or the presence of other plugins.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating high severity. Disclosure does not require authentication, which increases exploitability; attackers can reach the vulnerable endpoint via a crafted HTTP request. Although the EPSS score is not published and the flaw is not yet listed in the CISA KEV catalog, the combination of high impact, vector simplicity, and wide distribution means that exploitation is both feasible and potentially damaging.

Generated by OpenCVE AI on September 11, 2026 at 06:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Unlimited Elements For Elementor plugin to a version newer than 2.0.16 where the addontype input is properly validated and the query uses parameterized statements.
  • If an upgrade cannot be applied immediately, restrict external access to the plugin’s Ajax endpoints by applying IP allow/deny rules or by disabling the plugin until the fix is deployed.
  • Configure a Web Application Firewall to block suspicious SQL injection patterns in the addontype parameter, such as unexpected operators or concatenated statements.

Generated by OpenCVE AI on September 11, 2026 at 06:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Unitecms
Unitecms unlimited Elements For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Unitecms
Unitecms unlimited Elements For Elementor
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Unitecms Unlimited Elements For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:30:46.694Z

Reserved: 2026-08-01T17:37:42.275Z

Link: CVE-2026-18561

cve-icon Vulnrichment

Updated: 2026-09-11T16:34:22.848Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:20.480

Modified: 2026-09-11T21:17:08.637

Link: CVE-2026-18561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:45:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')