CVE-2026-92923 Unlimited Elements for Elementor SQL注入漏洞
影响低权限用户可盲注读取数据库任意数据
WordPress 插件 Unlimited Elements for Elementor 在 2.0.21 之前版本中,未对某参数进行过滤和转义即拼入 SQL 语句,导致 SQL 注入。攻击者可利用该缺陷执行盲注,读取数据库中的任意数据。
影响范围
Unlimited Elements for Elementor 2.0.21 之前版本受影响;2.0.18 起移除了订阅者级别访问权限,因此 2.0.18 至 2.0.21 之前需 Contributor 及以上角色才能利用,2.0.18 之前订阅者角色即可利用。
漏洞详情
漏洞类型为 SQL 注入,成因是插件将用户可控参数未经清理和转义直接用于 SQL 查询。攻击者通过构造恶意参数触发盲注,借助布尔或时间差异逐步推断数据库内容。低权限账户即可发起攻击,无需管理员权限。
利用条件与风险
利用前提是攻击者拥有订阅者(2.0.18 之前)或 Contributor 及以上(2.0.18 起)账户,实战中可用于窃取敏感数据,CVSS 6.3 属中危。
修复建议
官方修复方案为升级至 2.0.21 或更高版本;临时缓解措施包括限制低权限用户注册与投稿权限,或对相关参数进行输入过滤,暂无其他公开信息。
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.