CVE-2026-25007
8.5Element Invader · ElementInvader Addons for Elementor
A blind SQL injection vulnerability in Element Invader ElementInvader Addons for Elementor allows authenticated attackers to extract sensitive database information.
Executive summary
A blind SQL injection vulnerability in the ElementInvader Addons for Elementor plugin poses a high risk of sensitive data exposure for affected WordPress installations.
Vulnerability
The plugin fails to properly neutralize special elements used in SQL commands, resulting in a blind SQL injection vulnerability. This flaw requires the attacker to have at least low-level authenticated access to the WordPress environment to trigger the malicious query.
Business impact
Successful exploitation of this blind SQL injection vulnerability could allow an authenticated attacker to perform unauthorized queries against the WordPress database. Given the CVSS score of 8.5, this high-severity flaw may lead to the exfiltration of sensitive site configuration, user data, or credentials, potentially resulting in full site compromise or severe reputational damage.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should immediately deactivate and remove the ElementInvader Addons for Elementor plugin from the environment until a fix is released by the vendor.
Proactive Monitoring: Monitor database query logs for unusual patterns, such as unexpected time-based delays or attempts to access system tables, which are common indicators of blind SQL injection attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection patterns targeting WordPress plugins.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high CVSS severity and the potential for unauthorized data access, organizations must treat this vulnerability with urgency. We strongly recommend removing the vulnerable plugin immediately, as there is currently no confirmed vendor patch available to remediate the underlying code deficiency.
Sources
Originally found and disclosed by Nabil Irawan | Patchstack Bug Bounty Program, per the CVE Program record.