PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5486 Plugins CVE debrief

Unlimited Elements for Elementor for WordPress contains an authenticated SQL injection issue affecting versions up to and including 2.0.7. An attacker with Contributor-level access or higher may be able to abuse the get_cat_addons AJAX action to read sensitive database information, especially when they can obtain a valid Elementor nonce.

Vendor
Plugins
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-14
Advisory published
2026-05-14
Advisory updated
2026-05-14

Who should care

WordPress administrators, managed-hosting teams, and security owners running Unlimited Elements for Elementor version 2.0.7 or earlier, particularly sites that allow Contributor-level users or other non-admin content creators to access Elementor editor workflows.

Technical summary

The corpus attributes the flaw to the get_cat_addons AJAX action handling data[filter_search]. According to the advisory, normalizeAjaxInputData() applies stripslashes() to user input, which removes WordPress wp_magic_quotes() protection. The filter_search value is then passed through the deprecated wpdb->_escape() function and concatenated directly into a LIKE clause instead of being bound through prepared statements. That combination enables SQL injection from an authenticated request.

Defensive priority

Medium priority, with higher urgency on sites that expose Contributor-level or editor-level access to untrusted users and that store sensitive data in WordPress databases.

Recommended defensive actions

  • Confirm whether Unlimited Elements for Elementor is installed and treat version 2.0.7 and earlier as affected.
  • Apply the vendor update or replacement as soon as a fixed release is available; monitor the plugin advisory and WordPress plugin changelogs.
  • Restrict Contributor-level and Elementor editor access to trusted users only, and remove unnecessary accounts.
  • Audit web and application logs for suspicious requests to the get_cat_addons AJAX action and unusual database-related errors or responses.
  • If the plugin is not required, disable or remove it to reduce exposure; keep WordPress core and all plugins current.

Evidence notes

The supplied advisory text states the issue affects versions up to and including 2.0.7 and identifies the vulnerable path as data[filter_search] in the get_cat_addons AJAX action. The referenced source locations include unitecreator_actions.class.php, unitecreator_addons.class.php, provider_functions.class.php, and provider_db.class.php, along with a Wordfence write-up and the GitHub advisory record. The source item is marked advisoryType: unreviewed in the corpus, and no fixed version is provided there.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5486 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5486

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5486 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5486

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://github.com/advisories/GHSA-7q2p-8rmm-c8pg

    github_advisory_database

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/inc_php/unitecreator_actions.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/inc_php/unitecreator_addons.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/provider/provider_functions.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_db.class.php

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.