ZeroHour

CVE-2026-62109

large

Authenticated SQL Injection in Sky Addons for Elementor WordPress plugin

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-62109 is a SQL injection flaw (CWE-89) in the editor-facing functionality of the Sky Addons for Elementor WordPress plugin, affecting all versions up to and including 3.8.4. It is triggered over the network by an authenticated user with high privileges (administrator-level per the CVSS PR:High metric), with low attack complexity and no user interaction required. Because WordPress plugins query the site's shared database, a successful injection exposes sensitive database contents such as user credentials and password hashes (high confidentiality impact), with only low availability impact. Any WordPress site running the plugin at or below version 3.8.4 is affected; the plugin is an addon for the Elementor page builder, so only Elementor-based sites using this addon are in scope. There is no public proof-of-concept, the issue is not in CISA KEV, and no exploitation has been reported so far.

What to do: Update Sky Addons for Elementor to the latest patched release (any version newer than 3.8.4) as soon as it is available in the WordPress plugin directory. Until then, audit and limit administrator accounts, since only high-privileged users can trigger the injection, and review logs for unexpected administrator activity or anomalous database queries. No workaround is documented in the available data.

Affected
Sky Addons for Elementor (WordPress plugin)<= 3.8.4
Estimated exposure
large≈100,000+ sites (six-figure active-install count for the plugin on the WordPress.org directory) — Estimate based on the plugin's order-of-magnitude active-install count (six figures) on WordPress.org; only sites actively running version 3.8.4 or older are affected, and practical exploitation additionally requires administrator-level…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.