Elementor Pro RCE Flaw Under Active Attack
A critical Elementor Pro Forms module flaw allowing unauthenticated file uploads is under active attack against widely used WordPress sites.
A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload arbitrary files through the plugin's Forms module. The SOCRadar report indicates the flaw is being actively exploited in the wild. No CVE identifier was provided in the available text.
- Unauthenticated arbitrary file upload via Forms module
- Actively exploited per the report title
- Elementor Pro is a widely deployed WordPress plugin
- No CVE id given in the provided text
Elementor Pro RCE Flaw Under Active Attack A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin's Forms module. Trac
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.