Junglewise Threat Intelligence

CVE-2026-66626: SKT Addons for Elementor SQL injection

CVE-2026-66626 · Severity: high · CVSS 7.6 · Published 2026-09-17

Executive brief

SKT Addons for Elementor is a popular WordPress plugin that provides additional widgets and functionality for the Elementor page builder. A SQL injection vulnerability in versions 4.0 and earlier allows authenticated editors to execute arbitrary database queries, potentially exposing, modifying, or deleting sensitive user data and website content.

Technical details

The vulnerability is a SQL injection flaw in the SKT Addons for Elementor WordPress plugin (versions 4.0 and earlier) that requires an authenticated user with editor privilege level. An attacker with editor permissions can craft malicious input to execute arbitrary SQL queries against the WordPress database, allowing them to read, modify, or delete database contents including user accounts and private data. The vulnerability has been patched in version 4.1 and later. The attack vector requires network access and valid editor credentials on the target WordPress site.

Affected products

  • SKT Addons SKT Addons for Elementor ≤ 4.0

Timeline

  • 2026-09-08: disclosed: Reported by Ananda Dhakal (Patchstack)
  • 2026-09-17: advisory: Published by Patchstack
  • 2026-09-17: patched: Patched in version 4.1

References