DEV Community

Cover image for Elementor Pro Logic Flaw Allows Unauthenticated Remote Code Execution
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Elementor Pro Logic Flaw Allows Unauthenticated Remote Code Execution

Summary

Elementor Pro versions before 4.2.2 contain a critical logic flaw in the file upload module that allows unauthenticated attackers to bypass extension filters and execute arbitrary PHP code.

Take Action:

If you use Elementor Pro and have any form with a File Upload field, update the plugin to version 4.2.2 or later immediately. Then manually check the wp-content/uploads/elementor/forms/ folder on your server and delete any .php files you find there, because the update does not remove anything an attacker may have already uploaded.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)