CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

SQL Injection Vulnerability in Elementor Ally Plugin

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

An SQL injection vulnerability (CVE-2026-2313) in the Elementor Ally WordPress plugin, with over 400,000 installations, allows unauthenticated attackers to inject SQL queries via the URL path. The flaw affects versions up to 4.0.3 and can be exploited to steal sensitive data. Only 36% of users have updated to the patched version 4.1.0, leaving over 250,000 sites vulnerable. The vulnerability arises from insufficient escaping of user-supplied URL parameters in the `get_global_remediations()` method, enabling time-based blind SQL injection attacks. Exploitation requires the plugin to be connected to an Elementor account with the Remediation module active. WordPress 6.9.2, released recently, addresses multiple vulnerabilities, including XSS, authorization bypass, and SSRF flaws, and is recommended for immediate installation.

Timeline

  1. 11.03.2026 21:38 1 articles · 23h ago

    SQL Injection Vulnerability in Elementor Ally Plugin Disclosed

    An SQL injection vulnerability (CVE-2026-2313) in the Elementor Ally WordPress plugin, with over 400,000 installations, allows unauthenticated attackers to inject SQL queries via the URL path. The flaw affects versions up to 4.0.3 and can be exploited to steal sensitive data. Only 36% of users have updated to the patched version 4.1.0, leaving over 250,000 sites vulnerable. The vulnerability arises from insufficient escaping of user-supplied URL parameters in the `get_global_remediations()` method, enabling time-based blind SQL injection attacks. Exploitation requires the plugin to be connected to an Elementor account with the Remediation module active. WordPress 6.9.2, released recently, addresses multiple vulnerabilities, including XSS, authorization bypass, and SSRF flaws, and is recommended for immediate installation.

    Show sources

Information Snippets