Sceawere
Vulnerability Detail
CVE-2026-92923UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unlimited Elements SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- Unlimited Elements for Elementor
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-03T06:16:46.493Z",
"pubdate": "2026-10-03T06:16:46.493Z",
"executiveSummary": "The Unlimited Elements for Elementor WordPress plugin contains a critical SQL injection vulnerability arising from improper input sanitization and escaping protocols.\nThis security flaw allows authenticated attackers to manipulate SQL queries executed by the application, facilitating blind SQL injection attacks.\nBy injecting malicious SQL commands into vulnerable parameters, an attacker can extract sensitive information from the underlying database, potentially leading to unauthorized data disclosure and compromise of backend data integrity.\nThe vulnerability affects multiple versions of the plugin, with the attack surface and privilege requirements evolving across releases.\nIn versions prior to 2.0.18, subscribers could exploit the vulnerability, whereas versions 2.0.18 through 2.0.20 require at least Contributor-level access.\nThe risk is substantial, as successful exploitation does not require administrative privileges, significantly lowering the bar for malicious actors to perform data exfiltration within the WordPress environment.",
"technicalDetails": "The core vulnerability is a classic SQL injection flaw stemming from the insecure handling of user-supplied input before it is incorporated into database queries within the Unlimited Elements for Elementor plugin.\nThe root cause is the failure of the application to implement adequate sanitization and parameter binding when processing specific input parameters, which allows the input to be interpreted as executable SQL command structures rather than literal data.\nThe exploitation method relies on blind SQL injection techniques. Because the application does not directly reflect query results in the response, an attacker must infer information by observing differences in application behavior, such as timing delays or changes in page content, in response to boolean-based or time-based payloads.\nThe attack flow begins with an authenticated attacker—possessing either subscriber-level access (for versions < 2.0.18) or contributor-level access (for versions 2.0.18 to 2.0.20)—sending a crafted request to the vulnerable endpoint containing a malicious payload in the unsanitized parameter.\nUpon receiving the request, the application backend concatenates the tainted input into a SQL statement that is subsequently executed against the WordPress database.\nBy carefully constructing the payload, the attacker can manipulate the query logic (e.g., using UNION SELECT or conditional sleep statements) to bypass access controls, perform reconnaissance on the database schema, or exfiltrate sensitive data such as user hashes, configuration details, or other private content stored in the WordPress tables.\nThe impact of a successful exploitation is severe, as it grants unauthorized read access to the database layer. An attacker can systematically extract the contents of the database, potentially leading to a total breach of confidentiality for the WordPress instance.\nThe privilege escalation aspect of this vulnerability is noteworthy; while the initial access level was restricted in later versions, the underlying code-level flaw remains effectively the same, necessitating strict input validation as the primary resolution."
}