CVE-2026-24956: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24956 is a Blind SQL Injection vulnerability in the Download Manager Addons for Elementor WordPress plugin (wpdm-elementor) by Shahjada. It affects all versions through 1.3.0 and was reported on November 27, 2025, with public disclosure on February 11, 2026. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical/High), reflecting its unauthenticated, network-accessible nature with high confidentiality impact across scope boundaries (Patchstack, Feedly).

Technical details

The root cause is improper neutralization of special elements used in SQL commands (CWE-89), where user-supplied input is incorporated into database queries without adequate sanitization or parameterization. The vulnerability enables Blind SQL Injection, meaning an attacker cannot directly see query output but can infer database contents through boolean-based or time-based inference techniques. No authentication or user interaction is required, and the attack is conducted entirely over the network, making it trivially exploitable at scale. The vulnerability was discovered and credited to researcher NumeX (Patchstack).

Impact

Successful exploitation allows an unauthenticated remote attacker to extract sensitive data from the WordPress database, including user credentials, email addresses, private content, and configuration data. The CVSS scope is marked as Changed, indicating the vulnerability can affect resources beyond the plugin itself — potentially the entire WordPress database. Confidentiality impact is rated High, while integrity impact is None and availability impact is Low, suggesting the primary risk is unauthorized data disclosure rather than data modification or service disruption (Patchstack, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, indicating a currently low probability of near-term exploitation. However, Patchstack notes that SQL injection vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting WordPress sites regardless of traffic volume, and has issued a virtual patch (mitigation rule) for its users (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Download Manager Addons for Elementor plugin (wpdm-elementor) version ≤ 1.3.0 using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/wpdm-elementor/readme.txt.
  2. Identify vulnerable parameter: Probe plugin-specific endpoints or shortcode-rendered pages that interact with the database to locate parameters susceptible to SQL injection.
  3. Craft blind SQL injection payload: Since the vulnerability is blind, use boolean-based or time-based payloads (e.g., ' AND SLEEP(5)-- for time-based, or conditional true/false expressions for boolean-based) to confirm exploitability.
  4. Automate data extraction: Use a tool such as sqlmap with the identified vulnerable parameter to enumerate databases, tables, and extract sensitive data (e.g., sqlmap -u "<target_url>?param=value" --dbms=mysql --dump).
  5. Exfiltrate credentials: Target the wp_users table to extract hashed WordPress admin passwords, then attempt offline cracking using tools like Hashcat or John the Ripper.
  6. Escalate access: Use recovered credentials to log into the WordPress admin panel and achieve full site compromise (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to plugin-rendered pages containing SQL metacharacters (', --, SLEEP, UNION, AND 1=1, AND 1=2) in query parameters; repeated requests from a single IP with slight parameter variations indicative of automated blind SQL injection enumeration.
  • Logs: WordPress or web server access logs showing high volumes of requests to the same endpoint with incrementally modified parameters; entries containing URL-encoded SQL keywords (%27, %20AND%20, SLEEP%28).
  • Database: Unexpected or high-frequency database queries originating from the plugin's context; time-delayed query execution patterns consistent with SLEEP()-based probing visible in MySQL slow query logs.
  • Process: Anomalous database load or query spikes without corresponding legitimate traffic increases (Patchstack).

Mitigation and workarounds

The vendor has released version 2.0.0 of Download Manager Addons for Elementor, which resolves this vulnerability — all users should update immediately (Patchstack). If immediate upgrading is not possible, consider temporarily deactivating the plugin and contacting your hosting provider or web developer. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection rules (Patchstack has issued a virtual patch for its subscribers), implementing least-privilege database user permissions, and monitoring database logs for anomalous query patterns (Feedly).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a notable disclosure (Wordfence Blog). Patchstack, which coordinated the disclosure, classified it as High Priority and noted that SQL injection vulnerabilities of this CVSS score are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management