
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25007 is a Blind SQL Injection vulnerability in the ElementInvader Addons for Elementor WordPress plugin, affecting all versions through 1.4.2. The vulnerability was reported by researcher Nabil Irawan on December 19, 2025, and publicly disclosed on March 23–25, 2026. It carries a CVSS v3.1 base score of 8.5 (High), with a changed scope reflecting potential database-level impact beyond the application itself (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into SQL queries without adequate sanitization or parameterization. Exploitation requires only low-level authenticated access (e.g., Subscriber role) and no user interaction, making it accessible to a broad range of attackers. The attack is conducted over the network and leverages blind SQL injection techniques — where results are inferred from application behavior rather than direct error output — to enumerate and extract database contents (Patchstack).
Successful exploitation allows an authenticated attacker with minimal privileges to extract sensitive information from the WordPress database, including user credentials, personal data, and site configuration, without triggering visible errors. The changed scope in the CVSS rating indicates the impact extends beyond the plugin itself to the underlying database. Confidentiality impact is rated High, while integrity is unaffected and availability impact is Low, suggesting the primary risk is unauthorized data disclosure rather than data modification or service disruption (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
SLEEP() or conditional logic) to infer database structure and content without triggering visible errors.sqlmap with authenticated session cookies to systematically enumerate database tables, columns, and extract sensitive data such as WordPress user hashes or configuration values.SLEEP(), AND 1=1, OR 1=1, UNION SELECT).INFORMATION_SCHEMA lookups or time-delay functions.The vendor has released version 1.4.3 of ElementInvader Addons for Elementor, which patches this vulnerability; all users should upgrade immediately. As a temporary workaround, site administrators can use a Web Application Firewall (WAF) — Patchstack has issued a virtual patch/mitigation rule for its users. Additionally, restricting user registration or limiting Subscriber-level access on the site reduces the attack surface. Database user permissions should be scoped to the minimum required, and database activity should be monitored for anomalous query patterns (Patchstack).
Wordfence included CVE-2026-25007 in its weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as part of broader plugin security tracking. Patchstack, which discovered and disclosed the vulnerability through researcher Nabil Irawan, classified it as high priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites (Wordfence Weekly Report, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."