Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection.

This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
Published: 2026-05-25
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An injection flaw arises from improper neutralization of special characters in SQL commands, identified as CWE‑89. This flaw can lead to blind SQL injection, enabling attackers to extract sensitive data from the database or tamper with stored information, directly affecting confidentiality and integrity of the site’s data.

Affected Systems

The vulnerability impacts the Unlimited Elements For Elementor plugin for WordPress, covering all releases from the earliest version through 2.0.8. Users who have not yet upgraded to 2.0.9 or later are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score is not available, so the probability of exploitation remains uncertain, and the flaw is not listed in CISA's KEV catalog. The likely attack vector is through crafted HTTP requests to the plugin’s input endpoints, but no active exploits have been reported.

Generated by OpenCVE AI on May 25, 2026 at 23:50 UTC.

Remediation

Vendor Solution

Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin to the latest available version (at least 2.0.9).


OpenCVE Recommended Actions

  • Update the Unlimited Elements For Elementor plugin to version 2.0.9 or later
  • Restrict the plugin’s use to trusted administrators by disabling it for non‑admin roles
  • Monitor database logs and web traffic for anomalous SQL queries or error messages that may indicate injection attempts

Generated by OpenCVE AI on May 25, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Unlimited-elements
Unlimited-elements unlimited Elements For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Unlimited-elements
Unlimited-elements unlimited Elements For Elementor
Wordpress
Wordpress wordpress

Mon, 25 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
Title WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Unlimited-elements Unlimited Elements For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-26T10:51:35.869Z

Reserved: 2026-05-25T14:28:27.466Z

Link: CVE-2026-48837

cve-icon Vulnrichment

Updated: 2026-05-26T10:51:31.362Z

cve-icon NVD

Status : Received

Published: 2026-05-25T23:16:33.947

Modified: 2026-05-25T23:16:33.947

Link: CVE-2026-48837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T00:00:13Z

Weaknesses