A high-severity unauthenticated SQL injection vulnerability in Elementor’s Ally – Web Accessibility & Usability WordPress plugin (formerly One Click Accessibility) can allow attackers to extract sensitive data from affected sites, including potentially password hashes, by injecting SQL via the URL path. The flaw affects all versions up to 4.0.3 and is tied to how the plugin constructs a SQL JOIN using user-controlled input without proper SQL parameterization (i.e., not using wpdb->prepare()), enabling time-based blind SQL injection (e.g., CASE logic with SLEEP() delays) to exfiltrate data.
The issue was discovered by Drew Webber (Acquia) and reported through the Wordfence Bug Bounty Program; Wordfence coordinated disclosure with the vendor and a fix was released in Ally 4.1.0, with users urged to update. Technical write-ups note that while esc_url_raw() is applied, it does not prevent SQL metacharacters from being injected, leaving the query vulnerable in SQL context; one report also notes exploitation conditions may depend on the plugin being connected to an Elementor account. The two sources disagree on the CVE identifier (reported as CVE-2026-2413 vs CVE-2026-2313), but otherwise describe the same vulnerability, affected versions, and remediation guidance.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
By the time the vulnerability was publicly reported, WordPress.org data indicated only about 36% of affected sites had updated to the patched version. As a result, more than 250,000 websites were still potentially vulnerable despite the fix being available.
Elementor released Ally version 4.1.0 to fix the SQL injection vulnerability affecting all versions up to and including 4.0.3. Wordfence awarded the reporting researcher an $800 bug bounty for the finding.
Elementor acknowledged receipt of the vulnerability report concerning the Ally plugin. This marked the vendor's formal response before a patch was released.
Wordfence disclosed the Ally plugin SQL injection issue to Elementor through its bug bounty process after receiving the report from the researcher. The issue was later tracked as CVE-2026-2413 in multiple reports, though one source listed a conflicting CVE identifier.
Acquia security engineer Drew Webber discovered a high-severity unauthenticated SQL injection vulnerability in Elementor's Ally WordPress plugin affecting versions up to 4.0.3. The flaw stemmed from unsafe SQL query construction in the get_global_remediations() method and could enable time-based blind SQL injection under certain configuration conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.