Junglewise Threat Intelligence

CVE-2026-48837: Unlimited Elements For Elementor SQL injection

CVE-2026-48837 · Severity: high · CVSS 8.5 · Published 2026-05-25

Technologies: Unlimited Elements for Elementor. Vendors: Unlimited Elements.

Executive brief

Unlimited Elements For Elementor is a popular WordPress plugin used to add custom widgets and design elements to websites. A security flaw in this plugin allows an attacker with basic contributor-level access to perform a blind SQL injection attack. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising user data or site configuration.

Technical details

A Blind SQL Injection vulnerability exists in the Unlimited Elements For Elementor plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is present in versions up to and including 2.0.8. An attacker with 'Contributor' or higher privileges can exploit this vulnerability over the network without user interaction. By sending specially crafted requests, the attacker can interact directly with the database to extract sensitive information. The issue is addressed in version 2.0.9.

Affected products

  • Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.8

Timeline

  • 2026-05-05: other: Reported by researcher daroo
  • 2026-05-25: disclosed: CVE published by NVD
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-04: patched: Version 2.0.9 released

References

Related threats