CVE-2026-18561
Last modified
CVE-2026-18561 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| unitecms | Unlimited Elements For Elementor | <= 2.0.16 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18561?
How severe is CVE-2026-18561?
How do I fix CVE-2026-18561?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18549@fastify/multipart is a multipart form-data parser for Fasti…7.5
- CVE-2026-18550The Nokri - Job Board WordPress Theme for WordPress is vulne…9.8
- CVE-2026-18554IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote …7.5
- CVE-2026-18555The Better Messages – Chat Rooms, Group Chat, Private Messag…6.1
- CVE-2026-18556Authentication bypass using an alternate path or channel vul…7.4
- CVE-2026-1856The Appointment Booking Calendar plugin for WordPress is vul…6.4
- CVE-2026-18562The HUSKY – Products Filter Professional for WooCommerce plu…6.1
- CVE-2026-18567IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local a…4.7
- CVE-2026-18568XML::Sig versions from 0.29 before 0.72 for Perl allow signa…7.5
- CVE-2026-18569A flaw was found in the backchannel logout endpoint of the k…3.7
- CVE-2026-1857The Gutenberg Blocks with AI by Kadence WP plugin for WordPr…4.3
- CVE-2026-18570A flaw was found in the full-scope-disabled client-policy ex…5.4
Are you affected by CVE-2026-18561?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
