PatchSiren cyber security CVE debrief
CVE-2026-5486 Plugins CVE debrief
Unlimited Elements for Elementor for WordPress contains an authenticated SQL injection issue affecting versions up to and including 2.0.7. An attacker with Contributor-level access or higher may be able to abuse the get_cat_addons AJAX action to read sensitive database information, especially when they can obtain a valid Elementor nonce.
- Vendor
- Plugins
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-14
Who should care
WordPress administrators, managed-hosting teams, and security owners running Unlimited Elements for Elementor version 2.0.7 or earlier, particularly sites that allow Contributor-level users or other non-admin content creators to access Elementor editor workflows.
Technical summary
The corpus attributes the flaw to the get_cat_addons AJAX action handling data[filter_search]. According to the advisory, normalizeAjaxInputData() applies stripslashes() to user input, which removes WordPress wp_magic_quotes() protection. The filter_search value is then passed through the deprecated wpdb->_escape() function and concatenated directly into a LIKE clause instead of being bound through prepared statements. That combination enables SQL injection from an authenticated request.
Defensive priority
Medium priority, with higher urgency on sites that expose Contributor-level or editor-level access to untrusted users and that store sensitive data in WordPress databases.
Recommended defensive actions
- Confirm whether Unlimited Elements for Elementor is installed and treat version 2.0.7 and earlier as affected.
- Apply the vendor update or replacement as soon as a fixed release is available; monitor the plugin advisory and WordPress plugin changelogs.
- Restrict Contributor-level and Elementor editor access to trusted users only, and remove unnecessary accounts.
- Audit web and application logs for suspicious requests to the get_cat_addons AJAX action and unusual database-related errors or responses.
- If the plugin is not required, disable or remove it to reduce exposure; keep WordPress core and all plugins current.
Evidence notes
The supplied advisory text states the issue affects versions up to and including 2.0.7 and identifies the vulnerable path as data[filter_search] in the get_cat_addons AJAX action. The referenced source locations include unitecreator_actions.class.php, unitecreator_addons.class.php, provider_functions.class.php, and provider_db.class.php, along with a Wordfence write-up and the GitHub advisory record. The source item is marked advisoryType: unreviewed in the corpus, and no fixed version is provided there.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5486 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5486
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5486 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5486
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://github.com/advisories/GHSA-7q2p-8rmm-c8pg
github_advisory_database
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/inc_php/unitecreator_actions.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/inc_php/unitecreator_addons.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/2.0.6/provider/provider_functions.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php
Reference
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_db.class.php
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.