SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites
Over Security - Cybersecurity news aggregator [Unofficial]
March 11, 2026
An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication.
Discussion in the ATmosphere