Impact
An injection flaw arises from improper neutralization of special characters in SQL commands, identified as CWE‑89. This flaw can lead to blind SQL injection, enabling attackers to extract sensitive data from the database or tamper with stored information, directly affecting confidentiality and integrity of the site’s data.
Affected Systems
The vulnerability impacts the Unlimited Elements For Elementor plugin for WordPress, covering all releases from the earliest version through 2.0.8. Users who have not yet upgraded to 2.0.9 or later are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score is not available, so the probability of exploitation remains uncertain, and the flaw is not listed in CISA's KEV catalog. The likely attack vector is through crafted HTTP requests to the plugin’s input endpoints, but no active exploits have been reported.
OpenCVE Enrichment