cleantalk
Vulnerabilities and Security Researches

Unlimited Elements For Elementor (Free Widgets, Addons, Templates), CVE-2026-48837

CVE, Research URL

CVE-2026-48837

Published on
May 26, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
Affected versions
max 2.0.9.
Status
vulnerable