Description
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an editor‑based SQL injection flaw in SKT Addons for Elementor versions 4.0 and earlier. A crafted input can be injected into a database query, violating the integrity and confidentiality of stored data. This flaw is a classic CWE‑89 type injection issue.

Affected Systems

The affected product is Sonal S Sinha’s SKT Addons for Elementor plugin used in WordPress installations. All releases up to and including 4.0 are vulnerable; the latest 4.1 or higher contains the fix.

Risk and Exploitability

The CVSS score of 7.6 classifies the flaw as high severity, and although no EPSS score is available, the absence of KEV listing does not diminish the risk. The likely attack vector requires authenticated use of the editor interface, meaning that privileged users could exploit the injection to access or modify database contents.

Generated by OpenCVE AI on September 17, 2026 at 22:10 UTC.

Remediation

Vendor Solution

Update the WordPress SKT Addons for Elementor Plugin to the latest available version (at least 4.1).


OpenCVE Recommended Actions

  • Update the SKT Addons for Elementor plugin to the latest version 4.1 or newer.
  • If an update is not immediately possible, restrict editor access to trusted administrators only or deactivate the plugin until the patch is applied.
  • Apply robust input validation or use prepared statements when handling editor content to mitigate future injection attempts, following CWE‑89 best practices.

Generated by OpenCVE AI on September 17, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Title WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:53.896Z

Reserved: 2026-07-27T14:00:26.966Z

Link: CVE-2026-66626

cve-icon Vulnrichment

Updated: 2026-09-19T14:16:24.068Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:19.230

Modified: 2026-09-19T15:17:00.637

Link: CVE-2026-66626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')