SQL Injection Vulnerability in Unlimited Elements for Elementor Plugin by Unlimited Elements
CVE-2026-103355
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 October 2026
What is CVE-2026-103355?
A SQL Injection vulnerability has been identified in the Unlimited Elements for Elementor plugin, specifically affecting versions from n/a through 2.0.20. This flaw allows attackers to execute unauthorized SQL commands, potentially leading to data exposure. Proper input validation is critical to safeguard against such vulnerabilities, which can compromise the integrity and confidentiality of the database.
Affected Version(s)
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 0 <= 2.0.20