logo

SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites

ID: 10b6a157-9e2f-56f8-9ad7-2af9fdd03e61

STIX ID: report--10b6a157-9e2f-56f8-9ad7-2af9fdd03e61

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-03-11

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

An unauthenticated SQL injection (CVE-2026-2413) in the Elementor Ally accessibility plugin (≤4.0.3) permits attackers to inject SQL via a URL parameter in get_global_remediations(), enabling data extraction via time-based blind SQLi; the issue was fixed in version 4.1.0 but roughly 250,000+ sites remain unpatched and at risk, with exploitation contingent on the plugin being connected to an Elementor account and the Remediation module being active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.