SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites
11 March 2026 at 20:38
An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication. [...]