Elementor Pro 4.2.2 fixes a file-upload flaw under active attack
Attackers are exploiting a critical file-upload flaw in Elementor Pro 4.2.1 and earlier. Elementor shipped 4.2.2 as the fix. The CVSS is 9 and no login is needed.
Tag
14posts tagged #exploit.
Attackers are exploiting a critical file-upload flaw in Elementor Pro 4.2.1 and earlier. Elementor shipped 4.2.2 as the fix. The CVSS is 9 and no login is needed.
GiveWP shipped 4.16.7.2 for an unauthenticated PHP object-injection RCE with a CVSS of 10. The Events Calendar patched a similar bug in 6.17.3.1. A WPMU DEV Dashboard auth bypass has no fix. An old Pods privilege escalation resurfaced in a news write-up.
Attackers are now targeting WordPress sites that still run miniOrange SAML SSO 5.4.4 or older. Five more plugin CVEs also arrived, four of them without a fix.
wp2shell is a pre-authentication remote code execution chain in WordPress core (CVE-2026-63030 and CVE-2026-60137). What it is, whether you are affected, how to tell if your site was already hacked, and how to clean it.
Mailgun for WordPress 2.2.2 fixes an unauthenticated SSRF triggered by a path traversal in form handlers. Four more plugin CVEs published the same day include three that let anyone sign in as admin, and one PHP object injection in WS Form.
A loose boolean check in miniOrange SAML SSO let anyone sign in as an admin, and 5.4.5 fixes it. Other fixes cover a WooCommerce OTP token leak, a WPeMatico privilege escalation, an unauth RCE in a Contact Form 7 uploader, XSS in WPForms Pro, and a Dokan capability slip.
An unauthenticated action in JSON Options lets any visitor flip on user registration and set the default role to administrator. rtMedia, Events Made Easy and Depicter ship fixes; Persistent Login has none.
W3 Total Cache 2.10.5 blocks an unauthenticated write to any file on the server, including .htaccess. Broken Link Checker 2.4.12 closes a pre-auth RCE. Elementor Pro, TrueBooker and TabaPay Gateway also shipped critical fixes.
WP Compress ships version 7.20.01 to close a maximum-severity RCE that needs no login. Four other WordPress plugins carry critical bugs the same day, with two PHP object injections, one SQL injection, and one subscriber-level takeover.
A missing capability check in Frontend Admin by DynamiApps lets unauthenticated visitors escalate to administrator through a non-numeric user ID; update to 3.29.10 and audit accounts before other criticals in ProSolution WP Client, Solace Extra and ARForms.
An unauthenticated authorization bypass in Pods hands full admin to anyone who can reach the AJAX endpoint, and Templately's remote code execution needs only a subscriber account to fire.
Three unauthenticated authentication-bypass flaws in WordPress plugins were disclosed on the same day. Only User Profile Builder has shipped a fix; the other two remain open, alongside a critical file-deletion bug and two privilege-escalation flaws.
The link-factory plugin ships an operator-controlled REST API authenticated by a hardcoded Ed25519 key, and W3 Total Cache patches a stored XSS reachable through comment author names when its Lazy Load feature is enabled.
WordPress 7.0.3 fixes a pre-authentication reflected XSS on the login screen. A hardcoded backdoor shipped in one Advanced Responsive Video Embedder release, and The Events Calendar patched an author-level file read.