CVE-2026-62109: WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Sky Addons for Elementorto a version that resolves this vulnerability.Fixed in 3.8.5
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges. The affected attack vector is network-accessible and does not require user interaction, but an attacker must already have the necessary elevated permissions.
Which installations are affected?
Sky Addons for Elementor versions 3.8.4 and earlier are affected. The provided data does not state whether the vulnerable functionality is enabled in the default configuration.
What is the potential impact of successful exploitation?
Successful exploitation can expose confidential information and cause limited availability impact. The vulnerability is rated high severity with a CVSS score of 7.6, and integrity impact is listed as none.