CVE-2026-93527: WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability
Published Sep 23, 2026
·Updated
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
Affected Software
1 affected component
WordPress Live Copy Paste for Elementor<=1.5.10
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.5.11
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs Contributor-level access. The vulnerability is network-reachable, requires low attack complexity, and does not require user interaction.
2
Which plugin versions are affected?
Live Copy Paste for Elementor versions 1.5.10 and earlier are affected.
3
What is the potential impact of successful exploitation?
Successful exploitation can expose highly sensitive information and has a limited availability impact. The vulnerability may also affect resources beyond the vulnerable component because its scope is changed.