CVE-2026-92923 PUBLISHED

Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data

Assigner: WPScan
Reserved: 17.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.

Product Status

Vendor Unknown
Product Unlimited Elements for Elementor
Versions Default: unaffected
  • affected from 1.5.142 to 2.0.21 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE