PT-2026-104615 · WordPress · Unlimited Elements For Elementor

·

CVE-2026-103355

·

Published

2026-10-04

·

Updated

2026-10-05

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Unlimited Elements For Elementor versions prior to 2.0.21
Description Unlimited Elements for Elementor contains a blind SQL injection flaw. This issue allows unauthenticated remote attackers to extract arbitrary database records by failing to properly neutralize special elements used in an SQL command. Blind SQL injection is a technique that allows an attacker to infer data from a database by observing the application's response to specific queries.
Recommendations Update to version 2.0.21 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103355

Affected Products

Unlimited Elements For Elementor