Description
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Published: 2026-09-11
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Update Plugin
AI Analysis

Impact

The Sky Addons for Elementor plugin includes an SQL Injection flaw that permits attackers to inject arbitrary SQL through editor fields in WordPress sites. The vulnerability is caused by inadequate input validation, allowing malicious queries to be executed against the WordPress database. Successful exploitation could lead to data exfiltration, modification, or deletion, and might serve as a foothold for further attacks. The weakness is classified under CWE‑89 and carries a CVSS score of 7.6, indicating high severity.

Affected Systems

WordPress sites running Sky Addons for Elementor plugin version 3.8.4 or earlier are affected. Any installation that uses these plugin versions and relies on the editor functionality is at risk.

Risk and Exploitability

The attack path requires the vulnerability to be triggered via the web interface; any authenticated or unauthenticated user capable of interacting with the plugin editor can exploit the flaw. The EPSS score is less than 1%, indicating low exploitation probability. The CVSS score of 7.6 indicates high severity, but the vulnerability is not listed in CISA KEV. The web‑reachable vector and unsanitized input make the risk real for exposed sites.

Generated by OpenCVE AI on September 21, 2026 at 04:32 UTC.

Remediation

Vendor Solution

Update the WordPress Sky Addons for Elementor Plugin to the latest available version (at least 3.8.5).


OpenCVE Recommended Actions

  • Apply the latest version of the Sky Addons for Elementor plugin (at least 3.8.5).
  • If an update cannot be applied immediately, remove or disable the plugin from the WordPress installation.
  • Review and restrict access to the plugin’s editor interface, ensuring only trusted administrators can use it.

Generated by OpenCVE AI on September 21, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wowdevs
Wowdevs sky Addons For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wowdevs
Wowdevs sky Addons For Elementor

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Title WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Wordpress Wordpress
Wowdevs Sky Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T20:29:07.154Z

Reserved: 2026-07-13T06:15:10.221Z

Link: CVE-2026-62109

cve-icon Vulnrichment

Updated: 2026-09-11T18:59:15.441Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:43.720

Modified: 2026-09-11T21:17:12.120

Link: CVE-2026-62109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')