CVE-2026-85568: Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
Affected Software
Event History
Frequently Asked Questions
Are sites using the default widget configuration affected?
Exploitation requires a related widget option to be changed from its default setting. The issue is not described as affecting the default configuration.
What access does an attacker need to exploit this issue?
No authentication is required. An unauthenticated attacker can target the vulnerable ucs parameter when the relevant widget option is configured in the affected way.
What could an attacker obtain through successful exploitation?
Successful SQL injection can allow retrieval of non-public content.
Which versions need remediation?
Versions before 2.0.21 are affected, including the stated 1.5.139 through 2.0.20 range. Update to 2.0.21 or later.