PT-2026-104524 · WordPress · Unlimited Elements

·

CVE-2026-85568

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Unlimited Elements for Elementor WordPress plugin versions prior to 2.0.21
Description An issue exists where search values are not correctly handled before rewriting a prepared SQL statement. This allows unauthenticated users to perform SQL injection attacks to retrieve non-public content, provided a related widget option is configured differently from its default setting. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update the plugin to version 2.0.21 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85568

Affected Products

Unlimited Elements