CVE-2026-2503 | wpdive ElementCamp Plugin up to 2.3.6 on WordPress AJAX Action esc_sql sql injection
A vulnerability labeled as critical has been found in wpdive ElementCamp Plugin up to 2.3.6 on WordPress. The impacted element is the function esc_sql of the component AJAX Action Handler. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-2503. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.