CVE-2026-2313: Unauthenticated SQL Injection in Elementor Ally Plugin Impacts 250k+ Sites
Mar 11, 2026 // 23:30 - Tristan Wall


A critical SQL Injection (SQLi) vulnerability has been discovered in the Elementor Ally plugin, putting over 250,000 WordPress sites at risk of complete database takeover.

The Vulnerability: CVE-2026-0814

The flaw exists due to a lack of proper sanitization in the plugin’s dynamic query handler, which allows unauthenticated attackers to execute unauthorized SQL commands.

  • Root Cause: The plugin fails to use prepared statements when processing user-supplied data through its “Advanced Search” and “Live Filter” widgets.
  • Attack Vector: By sending a specially crafted web request, an attacker can bypass authentication, extract sensitive user data (including hashed passwords), and even gain administrative access to the WordPress dashboard.
  • Severity: This vulnerability has been assigned a CVSS score of 9.8 (Critical), as it requires no user interaction and can be easily automated.

Impact and Discovery

Researchers from Patchstack and Wordfence identified the flaw during a routine audit of popular Elementor add-ons.

  • Scale: With a quarter-million active installations, Elementor Ally is one of the most widely used layout-enhancing plugins for the Elementor ecosystem.
  • Active Exploitation: While there are no confirmed reports of mass exploitation yet, “Proof of Concept” (PoC) code has begun circulating on underground forums, making immediate action vital.

Mitigation and Fixes

The developers of Elementor Ally have released version 2.4.1 to address this security hole.

WAF Protection: Security providers like Cloudflare and Sucuri have deployed virtual patches for their firewall users to block known SQLi patterns targeting this plugin.

Update Immediately: If you are using Elementor Ally, navigate to your WordPress Dashboard > Updates and ensure you are running the latest version.

#250k+  #ally  #cve-2026-2313:  #elementor  #impacts  #injection  #news  #plugin  #sites  #sql  #unauthenticated   —   News