
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24956 is a Blind SQL Injection vulnerability in the Download Manager Addons for Elementor WordPress plugin (wpdm-elementor) by Shahjada. It affects all versions through 1.3.0 and was reported on November 27, 2025, with public disclosure on February 11, 2026. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical/High), reflecting its unauthenticated, network-accessible nature with high confidentiality impact across scope boundaries (Patchstack, Feedly).
The root cause is improper neutralization of special elements used in SQL commands (CWE-89), where user-supplied input is incorporated into database queries without adequate sanitization or parameterization. The vulnerability enables Blind SQL Injection, meaning an attacker cannot directly see query output but can infer database contents through boolean-based or time-based inference techniques. No authentication or user interaction is required, and the attack is conducted entirely over the network, making it trivially exploitable at scale. The vulnerability was discovered and credited to researcher NumeX (Patchstack).
Successful exploitation allows an unauthenticated remote attacker to extract sensitive data from the WordPress database, including user credentials, email addresses, private content, and configuration data. The CVSS scope is marked as Changed, indicating the vulnerability can affect resources beyond the plugin itself — potentially the entire WordPress database. Confidentiality impact is rated High, while integrity impact is None and availability impact is Low, suggesting the primary risk is unauthorized data disclosure rather than data modification or service disruption (Patchstack, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, indicating a currently low probability of near-term exploitation. However, Patchstack notes that SQL injection vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting WordPress sites regardless of traffic volume, and has issued a virtual patch (mitigation rule) for its users (Patchstack).
readme.txt files at /wp-content/plugins/wpdm-elementor/readme.txt.' AND SLEEP(5)-- for time-based, or conditional true/false expressions for boolean-based) to confirm exploitability.sqlmap with the identified vulnerable parameter to enumerate databases, tables, and extract sensitive data (e.g., sqlmap -u "<target_url>?param=value" --dbms=mysql --dump).wp_users table to extract hashed WordPress admin passwords, then attempt offline cracking using tools like Hashcat or John the Ripper.', --, SLEEP, UNION, AND 1=1, AND 1=2) in query parameters; repeated requests from a single IP with slight parameter variations indicative of automated blind SQL injection enumeration.%27, %20AND%20, SLEEP%28).SLEEP()-based probing visible in MySQL slow query logs.The vendor has released version 2.0.0 of Download Manager Addons for Elementor, which resolves this vulnerability — all users should update immediately (Patchstack). If immediate upgrading is not possible, consider temporarily deactivating the plugin and contacting your hosting provider or web developer. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection rules (Patchstack has issued a virtual patch for its subscribers), implementing least-privilege database user permissions, and monitoring database logs for anomalous query patterns (Feedly).
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a notable disclosure (Wordfence Blog). Patchstack, which coordinated the disclosure, classified it as High Priority and noted that SQL injection vulnerabilities of this CVSS score are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."