PT-2026-41840 · WordPress · Piotnet Addons For Elementor

Wannes Verwimp

·

Published

2026-05-19

·

Updated

2026-05-28

·

CVE-2026-4885

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piotnet Addons for Elementor Pro versions prior to 7.1.71
Description Missing file type validation in the pafe ajax form builder() function allows unauthenticated attackers to upload arbitrary files to the server. The plugin employs an incomplete extension blacklist that fails to block dangerous extensions such as .phar or .phtml, which may lead to remote code execution. This issue is only exploitable if a file field has been added to the form.
Recommendations Update to a version later than 7.1.70. As a temporary workaround, avoid adding file fields to forms until the update is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-4885

Affected Products

Piotnet Addons For Elementor