PT-2026-41840 · WordPress · Piotnet Addons For Elementor
Wannes Verwimp
·
Published
2026-05-19
·
Updated
2026-05-28
·
CVE-2026-4885
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piotnet Addons for Elementor Pro versions prior to 7.1.71
Description
Missing file type validation in the
pafe ajax form builder() function allows unauthenticated attackers to upload arbitrary files to the server. The plugin employs an incomplete extension blacklist that fails to block dangerous extensions such as .phar or .phtml, which may lead to remote code execution. This issue is only exploitable if a file field has been added to the form.Recommendations
Update to a version later than 7.1.70.
As a temporary workaround, avoid adding file fields to forms until the update is applied.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piotnet Addons For Elementor