
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2413 is an unauthenticated SQL Injection vulnerability in the Ally – Web Accessibility & Usability WordPress plugin (developed by Elementor/elemntor), affecting all versions up to and including 4.0.3. The flaw resides in the get_global_remediations() method, where a user-supplied URL parameter is directly concatenated into an SQL JOIN clause without adequate sanitization for SQL context. It was published on March 11, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). While the plugin applies esc_url_raw() to the URL parameter for URL-safety purposes, this function does not strip SQL metacharacters such as single quotes and parentheses, allowing them to pass through into a raw SQL JOIN clause concatenation in get_global_remediations() (Wordfence). Exploitation is possible via time-based blind SQL injection techniques, requiring no authentication or user interaction. A key precondition is that the plugin's Remediation module must be active, which in turn requires the plugin to be connected to an Elementor account (Wordfence). The vulnerable code path is documented in the plugin's source at modules/remediation/database/remediation-entry.php and modules/remediation/classes/utils.php (Wordfence).
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database via time-based blind SQL injection, posing a high confidentiality risk. Exposed data may include WordPress user credentials (hashed passwords), email addresses, session tokens, plugin configuration data, and any other content stored in the database. Integrity and availability are not directly impacted by this vulnerability, but credential exposure could enable follow-on attacks such as account takeover and lateral movement within the hosting environment (Wordfence, Security Affairs).
Exploitation has been reported in the wild, with activity tracked by exploit-intel.com and multiple threat intelligence sources (exploit-intel). The EPSS score is 0.1493 (~14.9%), indicating a meaningful probability of exploitation. Nuclei detection templates were added to the ProjectDiscovery nuclei-templates repository shortly after disclosure, enabling automated scanning (nuclei-templates). Qualys has also published a detection (ID: 531038) for this vulnerability (Qualys). No CISA KEV catalog listing was identified in the available data. The vulnerability is not listed as having a public PoC exploit, though exploitation has been reported (Wordfence).
get_global_remediations() method, which processes the URL path parameter.' AND SLEEP(5)-- - can confirm exploitability by measuring server response delay.sqlmap with time-based blind technique (--technique=T) against the vulnerable parameter to systematically extract database schema, table names, and sensitive data (e.g., wp_users table for credentials).', parentheses ()); repeated requests with incrementally varying payloads consistent with time-based blind SQLi enumeration; abnormally slow server responses (e.g., 5-second delays) correlated with specific requests.SLEEP(), BENCHMARK(), or heavy conditional expressions; queries originating from the WordPress database user that do not match normal application patterns.The vendor (Elementor) released a patch in plugin version 4.0.4 (changeset 3467513), which addresses the SQL injection by properly sanitizing the URL parameter before SQL concatenation (Wordfence). Immediate action: Update the Ally – Web Accessibility & Usability plugin to version 4.0.4 or later via the WordPress admin dashboard. As an interim workaround, disable the Remediation module within the plugin settings, or disconnect the plugin from the Elementor account to remove the precondition for exploitation. Additionally, deploy WAF rules to detect and block SQL injection patterns in HTTP request parameters, and apply the principle of least privilege to the WordPress database user account (Wordfence).
Wordfence, which discovered and disclosed the vulnerability, reported that approximately 400,000 WordPress sites are affected, generating significant media attention (Wordfence). Major security outlets including BleepingComputer, Security Affairs, SecurityWeek, Heise, TechRadar, and HackRead covered the disclosure, with some reporting the affected site count as 200,000–250,000 based on active install estimates at time of publication (BleepingComputer, SecurityWeek). The vulnerability was also discussed on Reddit's r/pwnhub and flagged by INCIBE (Spain's national cybersecurity agency), reflecting broad community awareness. ProjectDiscovery rapidly added multiple Nuclei detection templates following disclosure, underscoring the community's prioritization of this flaw (nuclei-templates).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."