Impact
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and retrieve non‑public content when a related widget option is set away from its default. This flaw permits attackers to inject arbitrary SQL through the 'ucs' parameter. Because the plugin does not properly sanitize the input before reusing a prepared statement, an unauthenticated user can execute malicious queries that read or modify non‑public content stored in the database, potentially compromising data confidentiality and integrity.
Affected Systems
WordPress sites running the Unlimited Elements for Elementor plugin versions 1.5.139 through 2.0.20, as indicated by the vulnerability title. Any site that has not upgraded to version 2.0.21 or later, and that has the vulnerable widget setting enabled, is vulnerable.
Risk and Exploitability
The vulnerability is reachable via a standard web request to the 'ucs' parameter and is therefore publicly exploitable from the internet. The absence of authentication or authorization controls means any network user can trigger the exploit. While a CVSS score is not listed, the nature of unauthenticated SQL injection typically indicates a high severity. EPSS information is unavailable, and the issue is not listed in the CISA KEV catalog. The attack path is straightforward and can result in significant data exposure or alteration.
OpenCVE Enrichment