Another worrying WordPress plugin security flaw could put 250,000 websites at risk



  • Ally WordPress plugin had a SQL injection flaw (CVE-2026-2413)
  • The vulnerability left ~246,600 sites exposed to data theft
  • Fixed in version 4.1.0; WordPress urges immediate updates

A popular WordPress plugin with hundreds of thousands of active installations had a high severity vulnerability that allowed malicious actors to steal sensitive data from websites, experts warned.

Ally is a web accessibility tool from Elementor, launched in November 2025 as a tool that not only identifies accessibility issues but also offers solutions and guides web administrators through the application process.



Leave a Comment

Your email address will not be published. Required fields are marked *