Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Published: 2026-10-03
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Patch Immediately
AI Analysis

Impact

The Unlimited Elements for Elementor plugin prior to version 2.0.21 fails to sanitise a parameter used in a SQL statement, enabling silent injection that allows an attacker with even subscriber privileges to extract data from the database. The type of weakness is a classic SQL injection flaw that directly compromises the confidentiality of stored data.

Affected Systems

WordPress sites running the Unlimited Elements for Elementor plugin versions 1.5.142 through 2.0.20 are affected. From version 2.0.18 onward, subscriber level users no longer have the required access, but contributors and higher roles remain vulnerable.

Risk and Exploitability

The exploit requires the attacker to supply a crafted request containing the vulnerable parameter; the likely attack vector is a web request through the plugin’s front‑end. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the ability for relatively low‑privileged users to read arbitrary database contents indicates a high potential impact. The CVSS score of 6.3 indicates medium severity, but the confidentiality risk remains significant.

Generated by OpenCVE AI on October 3, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Unlimited Elements for Elementor plugin to version 2.0.21 or later
  • If an update is not feasible, disable or delete the plugin to eliminate the attack surface
  • Verify that no users with Contributor or higher roles are allowed to interact with the vulnerable parameter through custom scripts or unauthorized access

Generated by OpenCVE AI on October 3, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Title Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:21.167Z

Reserved: 2026-09-17T11:18:42.089Z

Link: CVE-2026-92923

cve-icon Vulnrichment

Updated: 2026-10-03T15:00:20.365Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:46.493

Modified: 2026-10-03T16:16:43.650

Link: CVE-2026-92923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T16:30:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')