CVE-2026-66626: WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability
Published Sep 17, 2026
·Updated
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Affected Software
1 affected component
wordpress/skt-addons-for-elementor<=4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress SKT Addons for Elementor Pluginto a version that resolves this vulnerability.Fixed in 4.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Can an unauthenticated attacker exploit this issue?
No. The CVSS vector indicates that an attacker needs high privileges, and the description identifies the affected context as Editor SQL injection. No user interaction is required once the attacker has the necessary access.
2
What is the likely security impact of successful exploitation?
The CVSS vector indicates high confidentiality impact and low availability impact. It indicates no direct integrity impact, although the scope is marked as changed.