Another Worrying WordPress Plugin Security Flaw Could Put 250,000 Websites at Risk


  • Ally WordPress plugin had SQL injection vulnerability (CVE-2026-2413)
  • The vulnerability left around 246,600 sites exposed to data theft
  • Fixed in version 4.1.0; WordPress requests immediate updates

A popular WordPress plugin with hundreds of thousands of active installations had a high-severity vulnerability that allowed malicious actors to steal sensitive data from websites, experts have warned.

Ally is a web accessibility tool from Elementor, released in November 2025 as a tool that not only identifies accessibility issues, but also offers solutions and guides web administrators through the process of their application.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top