SQL Injection Vulnerability in Sky Addons for Elementor by Sky Addons
CVE-2026-62109

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 September 2026

What is CVE-2026-62109?

The Editor SQL Injection vulnerability found in versions of Sky Addons for Elementor prior to 3.8.4 allows attackers to manipulate database queries by injecting malicious SQL. If exploited, this may lead to unauthorized access to sensitive data and other severe security implications. It is crucial for users of Sky Addons for Elementor to update to the latest version to safeguard against potential exploitation.

Affected Version(s)

Sky Addons for Elementor <= 3.8.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.