Impact
The Sky Addons for Elementor plugin includes an SQL Injection flaw that permits attackers to inject arbitrary SQL through editor fields in WordPress sites. The vulnerability is caused by inadequate input validation, allowing malicious queries to be executed against the WordPress database. Successful exploitation could lead to data exfiltration, modification, or deletion, and might serve as a foothold for further attacks. The weakness is classified under CWE‑89 and carries a CVSS score of 7.6, indicating high severity.
Affected Systems
WordPress sites running Sky Addons for Elementor plugin version 3.8.4 or earlier are affected. Any installation that uses these plugin versions and relies on the editor functionality is at risk.
Risk and Exploitability
The attack path requires the vulnerability to be triggered via the web interface; any authenticated or unauthenticated user capable of interacting with the plugin editor can exploit the flaw. The EPSS score is less than 1%, indicating low exploitation probability. The CVSS score of 7.6 indicates high severity, but the vulnerability is not listed in CISA KEV. The web‑reachable vector and unsanitized input make the risk real for exposed sites.
OpenCVE Enrichment