DIRAS TAKE
Urgent: this is a remote, unauthenticated SQL injection with no vendor fix listed for 2.0.16 and earlier, so immediately reduce exposure and monitor for suspicious database queries.
What is CVE-2026-18561?
An unauthenticated attacker can run SQL injection against the Unlimited Elements For Elementor WordPress plugin, allowing database disclosure and data extraction. CVE-2026-18561 affects versions 2.0.16 and earlier in the 2.x branch. The flaw stems from unsafe handling of the addontype parameter that is incorporated into a WHERE clause without proper sanitization; no login, user interaction, or privileges are required beyond network access to a site that exposes the vulnerable plugin endpoints. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of unitecms Unlimited Elements For Elementor are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.0.16 and earlier |
Is CVE-2026-18561 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-18561
- Isolate and restrict access to WordPress admin-ajax and plugin endpoints from untrusted networks using a web application firewall or IP allowlists
- Monitor database and webserver logs for anomalous queries and repeated access to the plugin's AJAX endpoints
- Follow the vendor's guidance and apply a plugin update as soon as a fixed version is released
- Temporarily disable or remove the Unlimited Elements For Elementor plugin if you cannot adequately restrict access
Frequently asked questions
Is CVE-2026-18561 being actively exploited?
There are no public reports of active exploitation of CVE-2026-18561 as of 2026-09-30.
Which Unlimited Elements For Elementor versions are affected by CVE-2026-18561?
Unlimited Elements For Elementor versions 2.0.16 and earlier in the 2.x branch are reported as affected.
Is there a patch for CVE-2026-18561?
No fixed version is listed for this vulnerability; monitor the vendor for an official patch and apply it when available.
Does CVE-2026-18561 require authentication?
No, CVE-2026-18561 is an unauthenticated SQL injection and does not require a user account or privileged access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-18561
- cve.org/CVERecord?id=CVE-2026-18561
- wordfence.com/threat-intel/vulnerabilities/id/969d605d-e093-447c-abf7-0d56cb3ac569?source=cve
- plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/db.class.php#L216
- plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L87
- plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php#L1387
- plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addon.class.php#L304
- plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_functions.class.php#L611
- plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3661670%40unlimited-elements-for-elementor%2Ftrunk&old=3628543%40unlimited-elements-for-elementor%2Ftrunk&sfp_email=&sfph_mail=
- All unitecms CVEs on CVE Radar
- CVEs published in September 2026