Another worrisome WordPress plugin security flaw could put 250,000 websites at risk


  • Ally WordPress plugin had SQL injection vulnerability (CVE-2026-2413)
  • Vulnerability left ~246,600 websites vulnerable to data theft
  • Fixed in version 4.1.0; WordPress encourages immediate updates

A popular WordPress plugin with hundreds of thousands of active installations carried a serious vulnerability that allowed malicious actors to steal sensitive data from websites, experts have warned.

Ally is a web accessibility tool from Elementor, released in November 2025 as a tool that not only identifies accessibility issues, but also offers solutions and guides webmasters through the process of applying them.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top