CVE-2026-93527

8.5

bdthemes · Live Copy Paste for Elementor

A SQL injection vulnerability in the Live Copy Paste for Elementor WordPress plugin allows authenticated contributors to execute malicious database queries.

Executive summary

The Live Copy Paste for Elementor plugin contains a high-severity SQL injection vulnerability that permits authenticated contributors to potentially expose sensitive database information.

Vulnerability

This is a SQL injection vulnerability (CWE-89) arising from improper neutralization of special elements used in SQL commands. The vulnerability requires the attacker to hold at least Contributor-level privileges within the WordPress environment to trigger the flaw.

Business impact

The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive data stored within the WordPress database, including user credentials or configuration details. Given the CVSS score of 8.5, this represents a high-risk scenario where an internal user with limited privileges can escalate their impact to compromise back-end data integrity or confidentiality.

Remediation

Immediate Action: Update the Live Copy Paste for Elementor plugin to version 1.5.11 or the latest available version provided by the vendor.

Proactive Monitoring: Review database audit logs for anomalous SQL queries originating from user accounts with Contributor or higher permissions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns until the plugin update can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a significant risk to the confidentiality of your WordPress database. Security teams should prioritize the update of the Live Copy Paste for Elementor plugin to version 1.5.11 immediately. Failure to patch allows authenticated contributors to perform unauthorized database operations, necessitating swift remediation.

More bdthemes CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.