PT-2026-27881 · Unknown · Elementinvader Addons For Elementor

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25007

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions ElementInvader Addons for Elementor versions n/a through 1.4.2
Description The software contains a flaw due to improper neutralization of special elements within an SQL command, leading to a potential SQL injection. Specifically, the vulnerability allows for a blind SQL injection attack. The API endpoint and vulnerable parameters are not specified. The function names are not specified. There is no information about the number of potentially affected devices or real-world exploitation incidents.
Recommendations Update ElementInvader Addons for Elementor to a version later than 1.4.2.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25007

Affected Products

Elementinvader Addons For Elementor