Sceawere

Vulnerability Detail

CVE-2026-92923UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unlimited Elements SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
13h ago
Vendor
Unknown
Product
Unlimited Elements for Elementor
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-03T06:16:46.493Z",
  "pubdate": "2026-10-03T06:16:46.493Z",
  "executiveSummary": "The Unlimited Elements for Elementor WordPress plugin contains a critical SQL injection vulnerability arising from improper input sanitization and escaping protocols.\nThis security flaw allows authenticated attackers to manipulate SQL queries executed by the application, facilitating blind SQL injection attacks.\nBy injecting malicious SQL commands into vulnerable parameters, an attacker can extract sensitive information from the underlying database, potentially leading to unauthorized data disclosure and compromise of backend data integrity.\nThe vulnerability affects multiple versions of the plugin, with the attack surface and privilege requirements evolving across releases.\nIn versions prior to 2.0.18, subscribers could exploit the vulnerability, whereas versions 2.0.18 through 2.0.20 require at least Contributor-level access.\nThe risk is substantial, as successful exploitation does not require administrative privileges, significantly lowering the bar for malicious actors to perform data exfiltration within the WordPress environment.",
  "technicalDetails": "The core vulnerability is a classic SQL injection flaw stemming from the insecure handling of user-supplied input before it is incorporated into database queries within the Unlimited Elements for Elementor plugin.\nThe root cause is the failure of the application to implement adequate sanitization and parameter binding when processing specific input parameters, which allows the input to be interpreted as executable SQL command structures rather than literal data.\nThe exploitation method relies on blind SQL injection techniques. Because the application does not directly reflect query results in the response, an attacker must infer information by observing differences in application behavior, such as timing delays or changes in page content, in response to boolean-based or time-based payloads.\nThe attack flow begins with an authenticated attacker—possessing either subscriber-level access (for versions < 2.0.18) or contributor-level access (for versions 2.0.18 to 2.0.20)—sending a crafted request to the vulnerable endpoint containing a malicious payload in the unsanitized parameter.\nUpon receiving the request, the application backend concatenates the tainted input into a SQL statement that is subsequently executed against the WordPress database.\nBy carefully constructing the payload, the attacker can manipulate the query logic (e.g., using UNION SELECT or conditional sleep statements) to bypass access controls, perform reconnaissance on the database schema, or exfiltrate sensitive data such as user hashes, configuration details, or other private content stored in the WordPress tables.\nThe impact of a successful exploitation is severe, as it grants unauthorized read access to the database layer. An attacker can systematically extract the contents of the database, potentially leading to a total breach of confidentiality for the WordPress instance.\nThe privilege escalation aspect of this vulnerability is noteworthy; while the initial access level was restricted in later versions, the underlying code-level flaw remains effectively the same, necessitating strict input validation as the primary resolution."
}
CVE-2026-92923: Unlimited Elements SQL Injection Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere