---
id: CVE-2026-92923
title: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  sanitise and escape a parameter before using it in a SQL statement, allowing
  users with a role as low as subscriber to perform blind SQL injection attacks
  and r…
summary: >-
  The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not
  sanitise and escape a parameter before using it in a SQL statement, allowing
  users with a role as low as subscriber to perform blind SQL injection attacks
  and r…
severity: none
cwe:
  - CWE-89
product: Unlimited Elements for Elementor
affected:
  - unlimited_elements_for_elementor >= 1.5.142 < 2.0.21
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:46.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92923'
references:
  - url: 'https://wpscan.com/vulnerability/1d02096b-81c4-421b-a7d3-b0ed7b1d173b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.567Z'
---

## Overview

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
