Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
Published: 2026-10-03
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and retrieve non‑public content when a related widget option is set away from its default. This flaw permits attackers to inject arbitrary SQL through the 'ucs' parameter. Because the plugin does not properly sanitize the input before reusing a prepared statement, an unauthenticated user can execute malicious queries that read or modify non‑public content stored in the database, potentially compromising data confidentiality and integrity.

Affected Systems

WordPress sites running the Unlimited Elements for Elementor plugin versions 1.5.139 through 2.0.20, as indicated by the vulnerability title. Any site that has not upgraded to version 2.0.21 or later, and that has the vulnerable widget setting enabled, is vulnerable.

Risk and Exploitability

The vulnerability is reachable via a standard web request to the 'ucs' parameter and is therefore publicly exploitable from the internet. The absence of authentication or authorization controls means any network user can trigger the exploit. While a CVSS score is not listed, the nature of unauthenticated SQL injection typically indicates a high severity. EPSS information is unavailable, and the issue is not listed in the CISA KEV catalog. The attack path is straightforward and can result in significant data exposure or alteration.

Generated by OpenCVE AI on October 3, 2026 at 08:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Unlimited Elements for Elementor to version 2.0.21 or later
  • Remove or disable the widget setting that exposes the 'ucs' parameter, or set it back to the default value to prevent the vulnerability
  • Implement a web application firewall rule or server-side input validation to block or sanitize requests containing the 'ucs' parameter, limiting unauthenticated access

Generated by OpenCVE AI on October 3, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-89

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
Title Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T06:00:25.854Z

Reserved: 2026-09-04T10:01:47.700Z

Link: CVE-2026-85568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:43.507

Modified: 2026-10-03T06:16:43.507

Link: CVE-2026-85568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')