CVE-2026-103355
published 2026-10-04CVE-2026-103355: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free…
PriorityP262critical9.3CVSS 3.1
AVNACLPRNUINSCCHINAL
EPSS
0.25%
14.9th percentile
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress sql injection (EUVD-2026-92089)
vuldb·2026-10-04·CVSS 9.3
CVE-2026-103355 [CRITICAL] Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress sql injection (EUVD-2026-92089)
A vulnerability was found in Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes sql injection.
This vulnerability appears as CVE-2026-103355. The attack may be initiated remotely. There is no available exploit.
GHSA
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-el
ghsa_unreviewed·2026-10-04
CVE-2026-103355 [CRITICAL] CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-el
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-04
Published