Impact
The Unlimited Elements for Elementor plugin prior to version 2.0.21 fails to sanitise a parameter used in a SQL statement, enabling silent injection that allows an attacker with even subscriber privileges to extract data from the database. The type of weakness is a classic SQL injection flaw that directly compromises the confidentiality of stored data.
Affected Systems
WordPress sites running the Unlimited Elements for Elementor plugin versions 1.5.142 through 2.0.20 are affected. From version 2.0.18 onward, subscriber level users no longer have the required access, but contributors and higher roles remain vulnerable.
Risk and Exploitability
The exploit requires the attacker to supply a crafted request containing the vulnerable parameter; the likely attack vector is a web request through the plugin’s front‑end. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the ability for relatively low‑privileged users to read arbitrary database contents indicates a high potential impact. The CVSS score of 6.3 indicates medium severity, but the confidentiality risk remains significant.
OpenCVE Enrichment