Impact
The vulnerability is an editor‑based SQL injection flaw in SKT Addons for Elementor versions 4.0 and earlier. A crafted input can be injected into a database query, violating the integrity and confidentiality of stored data. This flaw is a classic CWE‑89 type injection issue.
Affected Systems
The affected product is Sonal S Sinha’s SKT Addons for Elementor plugin used in WordPress installations. All releases up to and including 4.0 are vulnerable; the latest 4.1 or higher contains the fix.
Risk and Exploitability
The CVSS score of 7.6 classifies the flaw as high severity, and although no EPSS score is available, the absence of KEV listing does not diminish the risk. The likely attack vector requires authenticated use of the editor interface, meaning that privileged users could exploit the injection to access or modify database contents.
OpenCVE Enrichment