Executive brief
Sky Addons for Elementor is a popular WordPress plugin that extends the Elementor page builder with additional design elements. The plugin contains a SQL injection flaw accessible to authenticated editors, allowing them to read, modify, or delete database contents including user accounts and sensitive data.
Technical details
A SQL injection vulnerability exists in Sky Addons for Elementor versions up to 3.8.4, triggered through unsanitized input in an editor-level action. The vulnerability requires editor-level or higher privileges, limiting the attack surface to authenticated users with editor capabilities. An attacker with these privileges can craft malicious SQL queries to exfiltrate, modify, or drop database records. The flaw has been patched in version 3.8.5.
Affected products
- Sky Addons Sky Addons for Elementor <=3.8.4
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fixed in version 3.8.5