CyberRota Analysis
AI-GeneratedTheGem (Elementor) versions up to 5.12.3 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries on the database. This critical vulnerability can lead to data exposure, manipulation, or complete system compromise. Organizations using these versions should prioritize immediate patching to mitigate potential exploitation risks.
CVE
CVE-2026-66609
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%
Original NVD Description
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.