SECURITYCRITICALCVE-2026-103355

CVE-2026-103355: Unlimited Elements For Elementor Blind SQL Injection

A critical, unauthenticated blind SQL injection in the Unlimited Elements For Elementor WordPress plugin (≤ 2.0.20) exposes site databases.

Dylan H.

Security Team

October 4, 2026
6 min read
CVE-2026-103355: Unlimited Elements For Elementor Blind SQL Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Unlimited Elements For Elementor (Free Widgets, Addons, Templates) — versions through 2.0.20

Overview

A critical, CVSS 9.3 blind SQL injection vulnerability has been disclosed in Unlimited Elements For Elementor (Free Widgets, Addons, Templates), a widely used WordPress plugin that extends the Elementor page builder with additional widgets, add-ons, and templates. Tracked as CVE-2026-103355 and classified under CWE-89 (SQL Injection), the flaw stems from improper neutralization of special elements used in an SQL command, and lets an unauthenticated attacker manipulate backend database queries through the plugin's terms_listing widget.

Because the injection is blind, the application never reflects query results directly back to the attacker. Instead, an attacker infers data by observing differences in the application's behavior — timing delays or boolean true/false responses — as they submit crafted payloads through the widget. The flaw was reserved with Patchstack's CNA on September 30, 2026 and published on October 4, 2026.

Public exploit-availability reporting is mixed: multiple vulnerability-intelligence feeds state that no standalone public exploit had been published in open research repositories as of publication, while at least one exploit-index listing shows a proof-of-concept already catalogued, described as a read-only boolean-oracle test that flips the terms_listing payload between a tautology and a falsity condition without using time-delay (SLEEP) payloads or extracting data. The CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no ransomware campaign has been linked to it.


Technical Details

FieldValue
CVE IDCVE-2026-103355
CWECWE-89 (SQL Injection)
SeverityCritical
CVSS 3.1 Score9.3
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack VectorNetwork (terms_listing widget)
AuthenticationNone required
Privileges RequiredNone
User InteractionNone
Affected SoftwareUnlimited Elements For Elementor — versions through 2.0.20
Fixed VersionNot yet published at disclosure time; vendor advisory indicates a fix is expected in a release beyond 2.0.20

How It Works

The terms_listing widget accepts input that is passed into a database query without adequate sanitization or parameterization. An attacker who can reach a page rendering the widget — which requires no authentication, no prior access, and no user interaction from a victim — can submit crafted values that alter the query's logic. Because the plugin does not return query output directly, exploitation relies on blind inference techniques: boolean-based payloads that flip a visible condition between true and false, or time-based payloads that introduce measurable delays, both of which let an attacker reconstruct database contents one bit at a time.

Why Blind SQLi Still Rates "Critical"

Blind SQL injection is often mistaken for a lower-impact bug because it never reflects data on screen the way a classic UNION-based injection does. That reasoning doesn't hold here: the CVSS vector's Confidentiality: High rating reflects that a patient attacker can still extract the full contents of the WordPress database — including user credentials, password hashes, and any other application data stored alongside Elementor content — purely by observing behavioral differences in automated requests. The Scope: Changed component of the vector also reflects that a successful attack can affect data outside the vulnerable component's own security authority, consistent with a flaw that touches the shared WordPress database layer.


Impact Assessment

Impact AreaDescription
Data ConfidentialityBlind SQLi can be used to exfiltrate the full WordPress database, including user tables, credentials, and session data, without ever appearing in visible output
Pre-Authentication ExposureNo account or privileges are needed — any site running the vulnerable widget on a public-facing page is reachable by anonymous attackers
Downstream CompromiseExtracted credentials or session tokens can be reused to pivot into the WordPress admin panel, enabling backdoor installation, defacement, or further lateral movement
Scale of ExposureUnlimited Elements For Elementor is a widely installed Elementor add-on; sites that render the terms_listing widget on any public page are exposed regardless of plugin configuration
Detection DifficultyBlind injection traffic can resemble normal requests at a glance, making the attack harder to spot in logs than error-based or UNION-based SQLi attempts

Who Is At Risk

Any WordPress site running Unlimited Elements For Elementor 2.0.20 or earlier with the terms_listing widget placed on a publicly reachable page is exposed. Sites built by agencies or templates that bundle this widget by default carry risk even if site owners are unaware the widget is in use, since no authentication is required to reach it.


Mitigation

Immediate Actions

  • Check your installed version of Unlimited Elements For Elementor in the WordPress plugin dashboard; any version 2.0.20 or earlier is affected.
  • Update to the latest available release as soon as the vendor ships a fixed version beyond 2.0.20. Check the plugin's WordPress.org changelog directly, since a confirmed patched version number was not available at time of publication.
  • If no patched release is yet available and the terms_listing widget is in use, consider temporarily removing or deactivating the widget/plugin on public-facing pages until a fix ships.

For Site Owners and Agencies

  • Audit which pages render the terms_listing widget and restrict or remove it from anonymous-facing pages where it is not essential.
  • Review database access logs and WAF logs for repeated requests with boolean-flip or timing-based payload patterns targeting the widget.
  • Rotate WordPress admin and database credentials if there is any indication of prior exploitation.

For Security Teams

  • Add Unlimited Elements For Elementor to vulnerability-scanning and WordPress asset-inventory scope for any managed client sites.
  • Deploy or update WAF rules to detect classic blind-SQLi probing patterns (boolean conditions, SLEEP/time-delay functions, UNION fragments) directed at Elementor widget endpoints.
  • Monitor for this CVE's addition to CISA's KEV catalog and treat it as a priority patch given the CVSS 9.3 score and unauthenticated attack path, regardless of current KEV status.

Key Takeaways

  1. CVE-2026-103355 is a CVSS 9.3 Critical blind SQL injection vulnerability in Unlimited Elements For Elementor, versions through 2.0.20, classified under CWE-89.
  2. The flaw lives in the plugin's terms_listing widget, which passes attacker-supplied input into a database query without adequate sanitization.
  3. No authentication, privileges, or user interaction are required — any attacker who can reach a page rendering the widget can attempt exploitation.
  4. Being "blind" does not reduce real-world risk: boolean- and time-based inference techniques can still fully exfiltrate database contents, including credentials.
  5. Exploit-availability reports conflict — some sources report no public PoC, others list one — and the CVE is not yet in CISA's KEV catalog, but the unauthenticated, pre-auth profile warrants prompt patching regardless.
  6. A confirmed fixed version was not available at disclosure time; site owners should watch for the vendor's next release and consider disabling the affected widget in the meantime.

Sources