---
id: CVE-2026-85568
title: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  correctly handle a search value before rewriting an already prepared SQL
  statement, allowing unauthenticated users to perform SQL injection attacks and
  to retri…
summary: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  correctly handle a search value before rewriting an already prepared SQL
  statement, allowing unauthenticated users to perform SQL injection attacks and
  to retri…
severity: none
cwe:
  - CWE-89
product: Unlimited Elements for Elementor
affected:
  - unlimited_elements_for_elementor >= 1.5.139 < 2.0.21
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:43.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85568'
references:
  - url: 'https://wpscan.com/vulnerability/f4f2c1c5-ced9-44cb-b605-a7ce12ac867f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.563Z'
---

## Overview

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
