Executive brief
Piotnet Addons for Elementor Pro is a popular WordPress plugin that extends the Elementor page builder with additional features. An unauthenticated attacker can upload arbitrary files to affected websites, potentially gaining full control of the server and compromising customer data, website functionality, and business operations. No official patch is currently available, making this a critical risk for any WordPress site using the affected plugin versions.
Technical details
This is an unauthenticated arbitrary file upload vulnerability in Piotnet Addons for Elementor Pro versions 7.1.67 and earlier. The vulnerable component fails to validate file uploads on a publicly accessible endpoint, allowing any attacker to upload malicious PHP or other executable files without authentication. An attacker can exploit this to upload a webshell, execute arbitrary code on the server, and achieve remote code execution (RCE) with the privileges of the web server process. User interaction is required—the exploit must be initiated via a privileged user performing an action such as clicking a link or visiting a crafted page—but the initial upload endpoint itself is unauthenticated. No official patch has been released as of the advisory date; temporary mitigation via Web Application Firewall (WAF) rules is recommended.
Affected products
- Piotnet Addons for Elementor Pro <=7.1.67
Timeline
- 2026-08-13: disclosed: Vulnerability reported by 0xd4rk5id3 and published by Patchstack