Elementor Pro 4.2.2 fixes a file-upload flaw under active attack
Attackers are exploiting a critical file-upload flaw in Elementor Pro 4.2.1 and earlier. Elementor shipped 4.2.2 as the fix. The CVSS is 9 and no login is needed.
Tag
22posts tagged #wordpress.
Attackers are exploiting a critical file-upload flaw in Elementor Pro 4.2.1 and earlier. Elementor shipped 4.2.2 as the fix. The CVSS is 9 and no login is needed.
Two WordPress plugins on roughly six million sites shipped fixes for unauthenticated RCE paths: All-in-One WP Migration via second-order SQL injection, Gravity Forms via a file upload that runs on NGINX.
GiveWP shipped 4.16.7.2 for an unauthenticated PHP object-injection RCE with a CVSS of 10. The Events Calendar patched a similar bug in 6.17.3.1. A WPMU DEV Dashboard auth bypass has no fix. An old Pods privilege escalation resurfaced in a news write-up.
A weak random number generator in BlogVault, MalCare and WP Remote let attackers derive the secret that binds a site to the remote management service and log in as administrator. Version 6.65 rebuilds the secret. Around 200,000 sites run the affected code.
Avada 7.16.1 fixes an unauthenticated remote code execution chain that needed Fusion Builder active too. TranslatePress 3.3.2 and InfusedWoo Pro 5.1.18 both close holes that handed an administrator password reset link to an attacker.
Attackers are now targeting WordPress sites that still run miniOrange SAML SSO 5.4.4 or older. Five more plugin CVEs also arrived, four of them without a fix.
wp2shell is a pre-authentication remote code execution chain in WordPress core (CVE-2026-63030 and CVE-2026-60137). What it is, whether you are affected, how to tell if your site was already hacked, and how to clean it.
ManageWP Worker fixes a signed login link anyone can replay to become admin. Four more plugins ship patches that let unauthenticated or low-level users become admin too.
Mailgun for WordPress 2.2.2 fixes an unauthenticated SSRF triggered by a path traversal in form handlers. Four more plugin CVEs published the same day include three that let anyone sign in as admin, and one PHP object injection in WS Form.
A loose boolean check in miniOrange SAML SSO let anyone sign in as an admin, and 5.4.5 fixes it. Other fixes cover a WooCommerce OTP token leak, a WPeMatico privilege escalation, an unauth RCE in a Contact Form 7 uploader, XSS in WPForms Pro, and a Dokan capability slip.
An unauthenticated action in JSON Options lets any visitor flip on user registration and set the default role to administrator. rtMedia, Events Made Easy and Depicter ship fixes; Persistent Login has none.
W3 Total Cache 2.10.5 blocks an unauthenticated write to any file on the server, including .htaccess. Broken Link Checker 2.4.12 closes a pre-auth RCE. Elementor Pro, TrueBooker and TabaPay Gateway also shipped critical fixes.
WP Compress ships version 7.20.01 to close a maximum-severity RCE that needs no login. Four other WordPress plugins carry critical bugs the same day, with two PHP object injections, one SQL injection, and one subscriber-level takeover.
WordPress 7.0.4 fixes an author-level remote code execution through Imagick's PostScript handling. Forminator 1.56.2 closes an unauthenticated arbitrary file upload on roughly 600,000 sites, and WPAdverts 2.3.3 patches an authorization bypass in its REST endpoint.
A missing capability check in Frontend Admin by DynamiApps lets unauthenticated visitors escalate to administrator through a non-numeric user ID; update to 3.29.10 and audit accounts before other criticals in ProSolution WP Client, Solace Extra and ARForms.
An unauthenticated authorization bypass in Pods hands full admin to anyone who can reach the AJAX endpoint, and Templately's remote code execution needs only a subscriber account to fire.
Three unauthenticated authentication-bypass flaws in WordPress plugins were disclosed on the same day. Only User Profile Builder has shipped a fix; the other two remain open, alongside a critical file-deletion bug and two privilege-escalation flaws.
The link-factory plugin ships an operator-controlled REST API authenticated by a hardcoded Ed25519 key, and W3 Total Cache patches a stored XSS reachable through comment author names when its Lazy Load feature is enabled.
A capability-mapping bug in Events Manager lets an unauthenticated visitor take over any admin account whose user ID matches one of the plugin's records, and four other WordPress plugins shipped critical fixes for RCE and payment-bypass holes.
WordPress 7.0.4 patches an author-level Imagick RCE that smuggles its payload inside a PNG, and five plugin criticals land on NVD — most of them pre-auth.
A supply-chain compromise in the BdThemes plugin ecosystem is pushing malicious payloads through a poisoned update API response, reaching sites that never installed anything new.
WordPress 7.0.3 fixes a pre-authentication reflected XSS on the login screen. A hardcoded backdoor shipped in one Advanced Responsive Video Embedder release, and The Events Calendar patched an author-level file read.