CVE-2026-62109
largeAuthenticated SQL Injection in Sky Addons for Elementor WordPress plugin
CVE-2026-62109 is a SQL injection flaw (CWE-89) in the editor-facing functionality of the Sky Addons for Elementor WordPress plugin, affecting all versions up to and including 3.8.4. It is triggered over the network by an authenticated user with high privileges (administrator-level per the CVSS PR:High metric), with low attack complexity and no user interaction required. Because WordPress plugins query the site's shared database, a successful injection exposes sensitive database contents such as user credentials and password hashes (high confidentiality impact), with only low availability impact. Any WordPress site running the plugin at or below version 3.8.4 is affected; the plugin is an addon for the Elementor page builder, so only Elementor-based sites using this addon are in scope. There is no public proof-of-concept, the issue is not in CISA KEV, and no exploitation has been reported so far.
What to do: Update Sky Addons for Elementor to the latest patched release (any version newer than 3.8.4) as soon as it is available in the WordPress plugin directory. Until then, audit and limit administrator accounts, since only high-privileged users can trigger the injection, and review logs for unexpected administrator activity or anomalous database queries. No workaround is documented in the available data.
| Sky Addons for Elementor (WordPress plugin) | <= 3.8.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.