Executive brief
Elementor Pro is a popular WordPress page builder plugin that includes a Forms widget allowing site owners to create contact and support forms with file upload fields. An unauthenticated attacker can exploit a logic flaw in the file upload validation to bypass extension checks and upload malicious PHP files to the web server, gaining remote code execution and complete control over the website.
Technical details
The vulnerability is an arbitrary file upload flaw in Elementor Pro versions 4.2.1 and below, specifically in the Forms module's File Upload field (modules/forms/fields/upload.php). The root cause is a logic mismatch between two independent loops: the validation loop returns early when it encounters an empty file entry (UPLOAD_ERR_NO_FILE) on a non-required field, preventing type-checks on subsequent files, while the process_field loop only skips the empty entry and continues processing remaining files. An unauthenticated attacker can submit a multi-part form with an empty file entry followed by a malicious .php file; the validator skips the PHP file entirely, but the processor writes it to a public directory with a .php extension, leading to remote code execution. No authentication or user interaction is required, as the Forms widget is publicly accessible. The patch is available in version 4.2.2.
Affected products
- Elementor Elementor Pro through 4.2.1
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Version 4.2.2 available
- 2026-08-19: kev added: Known to be exploited