CVE-2026-18561: unauthenticated sql injection in unitecms Unlimited Elements For Elementor

An unauthenticated attacker can run SQL injection against the Unlimited Elements For Elementor WordPress plugin, allowing database disclosure and data extraction. CVE-2026-18561 affects versions 2.0.16 and earlier in the 2.x branch. The flaw stems from unsafe handling of the addontype parameter that is incorporated into a WHERE clause without proper sanitization; no login, user interaction, or privileges are required beyond network access to a site that exposes the vulnerable plugin endpoints.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.5HIGH
EPSS
0.0033
CWE
CWE-89
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a remote, unauthenticated SQL injection with no vendor fix listed for 2.0.16 and earlier, so immediately reduce exposure and monitor for suspicious database queries.

What is CVE-2026-18561?

An unauthenticated attacker can run SQL injection against the Unlimited Elements For Elementor WordPress plugin, allowing database disclosure and data extraction. CVE-2026-18561 affects versions 2.0.16 and earlier in the 2.x branch. The flaw stems from unsafe handling of the addontype parameter that is incorporated into a WHERE clause without proper sanitization; no login, user interaction, or privileges are required beyond network access to a site that exposes the vulnerable plugin endpoints. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Which versions of unitecms Unlimited Elements For Elementor are affected?

BRANCHAFFECTEDFIXED
2.x2.0.16 and earlier

Is CVE-2026-18561 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-18561

  1. Isolate and restrict access to WordPress admin-ajax and plugin endpoints from untrusted networks using a web application firewall or IP allowlists
  2. Monitor database and webserver logs for anomalous queries and repeated access to the plugin's AJAX endpoints
  3. Follow the vendor's guidance and apply a plugin update as soon as a fixed version is released
  4. Temporarily disable or remove the Unlimited Elements For Elementor plugin if you cannot adequately restrict access

Frequently asked questions

Is CVE-2026-18561 being actively exploited?

There are no public reports of active exploitation of CVE-2026-18561 as of 2026-09-30.

Which Unlimited Elements For Elementor versions are affected by CVE-2026-18561?

Unlimited Elements For Elementor versions 2.0.16 and earlier in the 2.x branch are reported as affected.

Is there a patch for CVE-2026-18561?

No fixed version is listed for this vulnerability; monitor the vendor for an official patch and apply it when available.

Does CVE-2026-18561 require authentication?

No, CVE-2026-18561 is an unauthenticated SQL injection and does not require a user account or privileged access.

References