CVE-2024-6166: Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injection
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addonsorder’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Unlimited Elements For Elementor (Free Widgets, Addons, Templates)to a version that resolves this vulnerability.Fixed in 1.5.112 - Compensating control
Restrict plugin settings edit permissions so that only trusted administrators (not Contributor+) can edit plugin settings, since the vulnerability requires authenticated Contributor+ attackers with plugin setting edit permissions.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6166?
The severity of CVE-2024-6166 is classified as critical due to its vulnerability to time-based SQL Injection.
How do I fix CVE-2024-6166?
To fix CVE-2024-6166, update the Unlimited Elements For Elementor plugin to version 1.5.113 or later.
What is affected by CVE-2024-6166?
CVE-2024-6166 affects all versions of the Unlimited Elements For Elementor plugin for WordPress up to and including 1.5.112.
What could an attacker achieve with CVE-2024-6166?
An attacker could exploit CVE-2024-6166 to execute unauthorized SQL queries against the database.
Is CVE-2024-6166 specific to certain installations of WordPress?
No, CVE-2024-6166 affects any WordPress installation using the vulnerable versions of the Unlimited Elements For Elementor plugin.