CVE-2026-93527
8.5bdthemes · Live Copy Paste for Elementor
A SQL injection vulnerability in the Live Copy Paste for Elementor WordPress plugin allows authenticated contributors to execute malicious database queries.
Executive summary
The Live Copy Paste for Elementor plugin contains a high-severity SQL injection vulnerability that permits authenticated contributors to potentially expose sensitive database information.
Vulnerability
This is a SQL injection vulnerability (CWE-89) arising from improper neutralization of special elements used in SQL commands. The vulnerability requires the attacker to hold at least Contributor-level privileges within the WordPress environment to trigger the flaw.
Business impact
The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive data stored within the WordPress database, including user credentials or configuration details. Given the CVSS score of 8.5, this represents a high-risk scenario where an internal user with limited privileges can escalate their impact to compromise back-end data integrity or confidentiality.
Remediation
Immediate Action: Update the Live Copy Paste for Elementor plugin to version 1.5.11 or the latest available version provided by the vendor.
Proactive Monitoring: Review database audit logs for anomalous SQL queries originating from user accounts with Contributor or higher permissions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns until the plugin update can be applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to the confidentiality of your WordPress database. Security teams should prioritize the update of the Live Copy Paste for Elementor plugin to version 1.5.11 immediately. Failure to patch allows authenticated contributors to perform unauthorized database operations, necessitating swift remediation.
More bdthemes CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.