GHSA-fwfj-g2x9-rghpMediumCVSS 6.3
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape...
🔗 CVE IDs covered (1)
📋 Description
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.