Sceawere
Vulnerability Detail
CVE-2026-85568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unlimited Elements SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- Unlimited Elements for Elementor
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-03T06:16:43.507Z",
"pubdate": "2026-10-03T06:16:43.507Z",
"executiveSummary": "The Unlimited Elements for Elementor WordPress plugin, in versions prior to 2.0.21, contains a critical SQL injection vulnerability. The flaw allows unauthenticated remote attackers to inject arbitrary SQL commands into the database query structure, leading to unauthorized retrieval of non-public content.\nThis vulnerability stems from improper neutralization of user-supplied input before it is incorporated into a database query. Because the application fails to correctly sanitize search parameters within the widget-related functionality, an attacker can manipulate the query logic to bypass standard data access controls.\nThe risk implication is high, as the vulnerability is exploitable by unauthenticated users without requiring special privileges. Successful exploitation can lead to complete database exposure, potentially including sensitive site data, user information, or administrative credentials, depending on the database structure and underlying permissions. The vulnerability is triggered specifically when a non-default widget option is configured, necessitating a specific site configuration for the attack vector to remain active. Immediate remediation via version update is required to close this exposure.",
"technicalDetails": "The vulnerability resides in the data processing logic of the Unlimited Elements for Elementor plugin. The root cause is the improper handling of search values during the SQL statement construction process. The application attempts to use prepared statements; however, it incorrectly re-evaluates or rewrites these statements after the initial preparation phase, effectively nullifying the protection against SQL injection.\nSpecifically, when a user interacts with a widget that has been configured with non-default options, the plugin processes a search parameter intended to filter content. The vulnerability occurs because the plugin fails to maintain the integrity of the parameter binding during this secondary processing phase. Instead of treating the input as data, the application concatenates the user-supplied string directly into the SQL query logic.\nThe attack flow proceeds as follows: First, an unauthenticated actor identifies a widget component that utilizes the affected filtering/search functionality. By crafting a malicious request containing SQL syntax—such as UNION SELECT statements or conditional boolean tests—the attacker sends the payload to the server. Because the plugin does not properly sanitize or re-bind this input, the application interpreter executes the malicious SQL commands within the context of the database driver.\nThe vulnerable component involves the server-side code responsible for handling widget search requests. By manipulating these parameters, an attacker can bypass the intended query restrictions. This allows the adversary to perform unauthorized data extraction, potentially dumping entire tables from the WordPress database. Since the attack occurs at the SQL layer, the attacker can use information schema queries to map the database structure, identify sensitive tables (such as wp_users), and escalate the scope of the exfiltration.\nThis vulnerability is classified as an unauthenticated blind or union-based SQL injection. Given that no session or privilege escalation is required to reach the vulnerable code path, the network exposure is significant, as any internet-facing WordPress instance running the vulnerable plugin version is susceptible to automated exploitation attempts. The impact is persistent as long as the underlying query logic remains vulnerable to input concatenation during the search query build process."
}