CVE-2026-85568 PUBLISHED

Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter

Assigner: WPScan
Reserved: 04.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.

Product Status

Vendor Unknown
Product Unlimited Elements for Elementor
Versions Default: unaffected
  • affected from 1.5.139 to 2.0.21 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE