logo

Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk

ID: f88eba29-25e1-5f21-b849-643c4028fd1b

STIX ID: report--f88eba29-25e1-5f21-b849-643c4028fd1b

Feed Name: TechRepublic Security

Threat Score
60/100

Date Published: 2026-03-12

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

A critical SQL injection vulnerability (CVE-2026-2413) in the Elementor Ally WordPress accessibility plugin—installed on hundreds of thousands of sites—allows unauthenticated attackers to extract sensitive database information (including password hashes) when the plugin is connected to an Elementor account and its Remediation module is enabled; Wordfence published the technical details and Elementor has issued a patch, with recommended mitigations including updating the plugin, deploying WAFs, and limiting database privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.