CVE-2026-103338: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
unlimited-elements-for-elementorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Frequently Asked Questions
Which versions should be considered affected?
The affected range is listed as versions through 2.0.20. No lower bound is specified.
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low attack complexity, and low privileges are required. No user interaction is required.
What is the likely security impact of successful exploitation?
The vector indicates high confidentiality impact, no integrity impact, and low availability impact. It also indicates that the vulnerability can affect a security scope beyond the initially vulnerable component.