CVE-2026-92923: Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Unlimited Elements for Elementorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Frequently Asked Questions
Which users can exploit the issue in affected versions?
Versions before 2.0.18 can be exploited by authenticated users with the Subscriber role or higher. Versions 2.0.18 through 2.0.20 require a Contributor role or higher.
Is an unauthenticated attacker able to exploit this vulnerability?
No. The described attack requires an authenticated WordPress account with the required role.
What could an attacker obtain through exploitation?
An attacker can conduct blind SQL injection attacks to read arbitrary data from the WordPress database.
Which versions need remediation?
All versions before 2.0.21 are affected. Updating to version 2.0.21 or later addresses the issue.