CVE · High

CVE-2024-3055 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3055 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.5.105 1.5.105 2024-05-10

CVE-2024-3055

The Unlimited Elements For Elementor plugin for WordPress contains a time-based SQL injection vulnerability in the 'id' parameter affecting versions up to 1.5.102, arising from inadequate escaping of user input and improper SQL query preparation. Attackers with contributor-level permissions or higher can inject additional SQL commands to access sensitive database information. The vulnerability requires authentication and contributor access or above to exploit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.