Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk
ID: f88eba29-25e1-5f21-b849-643c4028fd1b
STIX ID: report--f88eba29-25e1-5f21-b849-643c4028fd1b
Feed Name: TechRepublic Security
A critical SQL injection vulnerability (CVE-2026-2413) in the Elementor Ally WordPress accessibility plugin—installed on hundreds of thousands of sites—allows unauthenticated attackers to extract sensitive database information (including password hashes) when the plugin is connected to an Elementor account and its Remediation module is enabled; Wordfence published the technical details and Elementor has issued a patch, with recommended mitigations including updating the plugin, deploying WAFs, and limiting database privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
