CVE-2026-2413Patch

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concatenated into an SQL JOIN clause without proper sanitization for SQL context. While `esc_url_raw()` is applied for URL safety, it does not prevent SQL metacharacters (single quotes, parentheses) from being injected. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection techniques. The Remediation module must be active, which requires the plugin to be connected to an Elementor account.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 19 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 17 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 9 mentions (2026-03-12); latest day: 1
  • 19 total mentions across 6 days

Deep dive

Activity timeline19 mentions / 6d
02579Mentions · 2026-03-10: 1Mentions · 2026-03-11: 3Mentions · 2026-03-12: 9Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-04-06: 1Active Exploitation · 2026-03-12: 3Active Exploitation · 2026-04-06: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 4Patch / Workaround · 2026-03-13: 4Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 8Technical Details · 2026-03-13: 4Technical Details · 2026-03-14: 1Technical Details · 2026-04-06: 103-1003-1103-1203-1303-1404-06
Signal classification4 categories
Patch
736.8%
Disclosure
736.8%
Active Exploitation
315.8%
General
210.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-03-113
Disclosure1General1Patch1
2026-03-129
Active Exploitation2Disclosure3General1Patch3
2026-03-134
Disclosure2Patch2
2026-03-141
Disclosure1
2026-04-061
Active Exploitation1
Full discourse19 posts
  • Hackread.com@HackRead
    Patch

    Over 200,000 #WordPress sites are exposed due to an SQL injection flaw in the Ally plugin (CVE-2026-2413), allowing attackers to extract database data. Patch released, but many sites remain vulnerable. Read: https://hackread.com/sql-injection-vulnerability-ally-wordpress-plugin/ #CyberSecurity #SQLInjection #Vulnerability

    Post summary

    CVE-2026‑2413 is an SQL injection vulnerability in the Ally WordPress plugin that has exposed over 200,000 sites, and a patch has been released—though many sites remain vulnerable.

    0411011.2K
    114.3K followersView on X
  • Wordfence@wordfence
    Patch

    400,000 WordPress Sites Affected by Unauthenticated SQL Injection Vulnerability in Ally WordPress Plugin The vulnerability allows unauthenticated attackers to extract sensitive data from the database via time-based blind SQL injection. CVE-2026-2413 has a CVSS score of 7.5 (High). Discovered by Drew Webber (mcdruid) through the Wordfence Bug Bounty Program, the vulnerability was patched in version 4.1.0. Review the report to ensure your site is not affected. https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/

    Post summary

    CVE-2026-2413, an unauthenticated time-based blind SQL injection in the Ally WordPress plugin, has been patched in version 4.1.0; 400,000 sites may be affected, so users should verify patch status.

    02091302
    8.2K followersView on X
  • Shakquraa | Cybersecurity@shakquraa
    Patch

    🚨 CVE-2026-2413: An SQL injection issue in the Ally plugin could let attackers access database data on 200K+ #WordPress sites. Patch available, but adoption is still lagging.

    Post summary

    The post announces CVE‑2026‑2413, an SQL injection flaw in the Ally plugin, noting that a patch exists but uptake remains low.

    01041410
    1.1K followersView on X
  • TechNadu@TechNadu
    Patch

    Security alert 🚨 A high-severity SQL injection flaw (CVE-2026-2413) in the Ally WordPress Plugin from Elementor could expose data from 250K+ sites. The issue was discovered by Drew Webber at Acquia. Update to v4.1.0. Follow @TechNadu for cyber alerts. #CyberSecurity #WordPress https://t.co/QfeVT3IhlH

    Post summary

    The alert announces a high‑severity SQL injection vulnerability (CVE‑2026‑2413) in the Elementor Ally WordPress plugin and advises updating to v4.1.0 to mitigate the risk.

    1001077
    10.0K followersView on X
  • SwissWPSecure@Swisswpsecure
    Active Exploitation

    🔴 WP ALERT — April 6, 2026 4 active CVEs. Act today: 🔴 W3 Total Cache CVE-2026-27384 (CVSS 9.8) — RCE, no login needed → update to 2.9.2 🔴 Royal Elementor CVE-2026-28135 — no reliable patch → DELETE it 🟠 Gutenverse CVE-2026-2924 — Stored XSS → update to 3.4.7 🟠 Ally CVE-2026-2413 — blind SQLi, unauthenticated → update to 4.0.4+ Exploits hit in 5hrs median. SwissWPSuite WAF + Sentinel blocks 3 of 4. Royal Elementor must be deleted — we tell you the truth. Full brief → https://swisswpsecure.com/%f0%9f%94%b4-wordpress-security-alert-april-6-2026-4-active-threats-you-must-act-on-today/ #WPSec #WordPress 🛡️

    Post summary

    The alert warns of four high‑CVSS WordPress vulnerabilities that are reportedly being actively exploited and provides specific update or removal instructions.

    0001049
    1 followersView on X
  • Cyber News Live@cybernewslive
    Disclosure

    A serious security flaw in the Ally WordPress plugin — used on more than 400,000 websites — lets attackers steal data directly from a site's database without logging in. The flaw, tracked as CVE-2026-2413, allows criminals to extract administrator accounts, email addresses, password hashes, and other sensitive records by sending a specially crafted web address. A fix was released on February 23, but as of March 11, roughly 60% of sites — more than 200,000 — were still running the vulnerable version. If you use a website running WordPress, contact the site owner to confirm they've updated the Ally plugin to the latest version. 💥 #CyberNewsLive https://hackread.com/sql-injection-vulnerability-ally-wordpress-plugin/

    Post summary

    The text announces a new SQL‑injection flaw (CVE‑2026‑2413) in the Ally WordPress plugin, details its impact, and highlights the availability of a patch issued on February 23 with a call for site owners to update.

    0000160
    1.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-2413 - high 🚨 Ally – Web Accessibility & Usability <= 4.0.3 - SQL Injection > The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL In... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-2413 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the discovery of a high‑severity SQL injection vulnerability in the Ally – Web Accessibility & Usability WordPress plugin, detailing affected versions and the nature of the flaw.

    00001145
    902 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    A SQL injection flaw (CVE-2026-2413) in the Ally WordPress plugin exposed over 200,000 sites to data extraction via time-based blind SQL attacks. Ally 4.1.0 patch adds sanitization, but 60% remain vulnerable. #WordPress #SQLInjection #USA https://ift.tt/IfEG6X7

    Post summary

    CVE-2026-2413 is a SQL injection flaw affecting over 200,000 WordPress sites, actively exploited via time‑based blind SQL attacks; a patch exists (Ally 4.1.0) but many sites remain vulnerable.

    00010126
    3.7K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Critical SQL Injection bug in Ally plugin threatens 400,000+ WordPress sites: An unauthenticated SQL injection flaw (CVE-2026-2413) in the Ally WordPress plugin, used on 400K+ sites, could allow attackers to steal sensitive data. An unauthenticated SQL… https://securityaffairs.com/189354/security/critical-sql-injection-bug-in-ally-plugin-threatens-400000-wordpress-sites.html?utm_source=dlvr.it&utm_medium=twitter https://t.co/9mYiXosjEa

    Post summary

    The article announces a critical unauthenticated SQL injection flaw in the Ally WordPress plugin, affecting over 400,000 sites, but does not provide a PoC, exploit code, or patch information.

    0100042
    2.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical SQL injection flaw (CVE-2026-2413) in the Ally WordPress plugin exposes 400K+ sites to database theft. Update to version 4.1.0 immediately. https://securityonline.info/high-severity-sql-injection-in-ally-wordpress-plugin-threatens-400k-sites/ https://t.co/WZAA0ZODNx

    Post summary

    The post alerts about a critical SQL injection in the Ally WordPress plugin, warns that 400K+ sites are exposed, and urges users to upgrade to version 4.1.0.

    00001293
    10.6K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Ally WordPress Plugin SQL Injection Flaw Leaves 250,000 Sites Exposed to Database Theft SC Media reports that CVE-2026-2413 in the Ally accessibility plugin allows unauthenticated SQL injection, enabling attackers to read, modify, or delete database content when specific modules are enabled. This matters because only about 36% of sites had patched, leaving at least 250,000 WordPress installations exposed to potential sensitive data compromise. 🎯 Target: Global/WordPress Websites #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/high-severity-wordpress-plugin-flaw-poses-data-compromise-risk

    Post summary

    SC Media reports that CVE-2026-2413, a SQL injection flaw in the Ally WordPress plugin, exposes roughly 250,000 sites, with only about 36% having applied the available patch.

    0000034
    285 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Ally WordPress Plugin SQL Injection Flaw Leaves 200,000+ Sites Exposed A critical SQL injection flaw, tracked as CVE-2026-2413, in the Ally WordPress plugin can let unauthenticated attackers extract sensitive database data from vulnerable sites. It matters because over 200,000 installations reportedly remained unpatched despite a fix being available, creating a broad window for automated mass exploitation. 🎯 Target: Global/Websites #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://hackread.com/sql-injection-vulnerability-ally-wordpress-plugin/

    Post summary

    A critical SQL injection vulnerability (CVE-2026-2413) in the Ally WordPress plugin remains unpatched on 200,000+ sites, with a fix available but no proof of active exploitation or PoC provided.

    0000036
    285 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Critical SQL injection flaw CVE-2026-2413 in Ally WordPress plugin exposes 400,000+ sites, allowing unauthenticated data theft. Admins urged to patch promptly. #WordPress https://threatcluster.io/cluster/critical-sql-injection-vulnerability-in-ally-plugin-affects--2219902a

    Post summary

    The post highlights a critical SQL injection flaw affecting hundreds of thousands of WordPress sites, urges immediate patching, and indicates that exploitation is already occurring.

    0000043
    100 followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    Unauth SQLi in the Ally WordPress plugin (CVE-2026-2413) puts 400K+ sites at risk. Devs used esc_url_raw() instead of wpdb->prepare() - a textbook parameterization miss. Patch to v4.1.0 now. https://securityaffairs.com/189354/security/critical-sql-injection-bug-in-ally-plugin-threatens-400000-wordpress-sites.html #cybersecurity #WordPress #SQLinjection #infosec

    Post summary

    The post announces an unauthenticated SQL injection in the Ally WordPress plugin, notes that 400K+ sites are affected, and highlights the release of patch v4.1.0.

    0000041
    12 followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    [Security Affairs] Critical SQL Injection bug in Ally plugin threatens 400,000+ WordPress sites. An unauthenticated SQL injection flaw (CVE-2026-2413) in the Ally WordPress plugin, used on 400K+ sites, could allow attackers to steal sensitive data.... http://ow.ly/j5Ta106vLXY

    Post summary

    A critical unauthenticated SQL injection vulnerability (CVE-2026-2413) affecting the Ally WordPress plugin has been disclosed, impacting more than 400,000 sites, but no evidence of exploitation or PoC has been shared.

    0000042
    2.2K followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Active Exploitation

    CVE-2026-2413 exposes a SQL injection flaw in the Elementor Ally WordPress plugin, allowing unauthenticated attackers to extract sensitive database data from over 250,000 unpatched sites. https://www.bleepingcomputer.com/news/security/sqli-flaw-in-elementor-ally-plugin-impacts-250k-plus-wordpress-sites/

    Post summary

    CVE-2026-2413 is an unauthenticated SQL injection flaw in the Elementor Ally plugin that is actively exploited, allowing attackers to exfiltrate database data from more than 250,000 unpatched WordPress sites.

    0000063
    227 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2413 - elemntor - Ally – Web Accessibility & Usability - https://www.redpacketsecurity.com/cve-alert-cve-2026-2413-elemntor-ally-web-accessibility-usability/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2413 #elemntor #ally-web-accessibility-and-usability

    Post summary

    The tweet merely cites a CVE alert and links to an advisory, providing no PoC, exploit code, patch or technical specifics.

    0000072
    3.5K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    General

    @BleepinComputer I'm a Japanese security researcher who always references your articles. The CVE number listed in this article is not CVE-2026-2313, but I believe the correct number is "CVE-2026-2413" (https://www.cve.org/CVERecord?id=CVE-2026-2413). Please check it out. Thank you as always.

    Post summary

    The tweet is simply correcting the CVE number associated with a vulnerability, without providing additional technical, exploit, or mitigation details.

    00000346
    11.4K followersView on X
  • ctrlaltnod@ctrlaltnod
    Disclosure

    Critical SQL Injection Vulnerability Exposes 250,000+ WordPress Sites Unauthenticated SQL injection in Elementor Ally plugin exposes database breaches. CVE-2026-2413 affects 250K+ sites w... #Vulnerabilities #Cybersecurity #CyberNews #InfoSec https://www.ctrlaltnod.com/news/critical-sql-flaw-hits-250-000-wordpress-sites-via-plugin/

    Post summary

    CVE-2026-2413 is an unauthenticated SQL injection flaw in the Elementor Ally WordPress plugin, reported to affect over 250,000 sites, with no PoC, exploit code, patch, or active exploitation details provided.

    0000085
    283 followersView on X

Explore more